Trojan

Trojan.Win32.Miner.axtyx removal instruction

Malware Removal

The Trojan.Win32.Miner.axtyx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.axtyx virus can do?

  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the CoinMiner02 malware family
  • A cryptomining command was executed
  • Anomalous binary characteristics

How to determine Trojan.Win32.Miner.axtyx?


File Info:

name: 80E7BCE107C9F011FC33.mlw
path: /opt/CAPEv2/storage/binaries/7a5acf33fdb4674354f04f5546e572358197eb8bfbfe9d403652f4efdac53dba
crc32: FD1B81A1
md5: 80e7bce107c9f011fc338d0416f58030
sha1: b594ea98b235e26a69315288efc200bae39a2a65
sha256: 7a5acf33fdb4674354f04f5546e572358197eb8bfbfe9d403652f4efdac53dba
sha512: af38a3d3c0e4bd351ff310c10cd32a5b802d2654b04c591834dcddea9420317275bc9b2ee911544a72a373d28a40875d8e1ccc98b5010204929d47a6fb36f58a
ssdeep: 49152:vgwRux8q4fQxtJGNIzyr5mOZrh5+I1Jq4LgRUMYeC4VkABkCRUu+jzQ5UIjVl:vgwRueq4fQxtgSzyrIsxBsYeC4VNZRUc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122B523F0AFF179F8E04132767858B23D33E2AD4D8F1460A7E68AF51664309C592F5A4B
sha3_384: e324e724368031893bf846e170a431cef330ffe9683d605ac18dee184cbf614813ad996a2a771888af1385b5d6565c2b
ep_bytes: 558bec6aff6870c4410068c095410064
timestamp: 2012-12-31 00:38:51

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

Trojan.Win32.Miner.axtyx also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Miner.4!c
MicroWorld-eScanTrojan.Sesfix.3
CAT-QuickHealScript.Trojan.38726
ALYacApplication.Generic.3006135
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 005622c31 )
BitDefenderTrojan.Sesfix.3
K7GWRiskware ( 005622c31 )
CyrenTrojan.AIIF-3
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win64/CoinMiner.PO potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.axtyx
AlibabaTrojan:Win32/Miner.4778f330
RisingHackTool.XMRMiner!1.C2EC (CLASSIC)
EmsisoftTrojan.Sesfix.3 (B)
DrWebTool.BtcMine.2562
TrendMicroCoinminer.BAT.MALXMR.COMP
McAfee-GW-EditionCoinminer.json.g
FireEyeTrojan.Sesfix.3
SophosGeneric Reputation PUA (PUA)
JiangminTrojan.Miner.qkn
AviraHEUR/AGEN.1202894
MAXmalware (ai score=75)
Antiy-AVLTrojan/Generic.ASMalwS.34867F0
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Vigorf.A
GDataWin32.Application.Coinminer.FC8EHE
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4198781
McAfeeArtemis!80E7BCE107C9
VBA32Trojan.Miner
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallCoinminer.BAT.MALXMR.COMP
TencentScript.Risk.Bitminer.Eaxb
YandexRiskware.Agent!Yybw35RbNq4
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/BtcMineNET.2!tr
AVGBV:Miner-HA [PUP]
Cybereasonmalicious.107c9f
AvastBV:Miner-HA [PUP]

How to remove Trojan.Win32.Miner.axtyx?

Trojan.Win32.Miner.axtyx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment