Categories: Trojan

How to remove “Trojan.Win32.Miner”?

The Trojan.Win32.Miner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner virus can do?

  • Anomalous binary characteristics

How to determine Trojan.Win32.Miner?


File Info:

crc32: D91CAB28md5: 37bd2acae3abad014bb450cc2e34fe34name: uimgrbroker.exesha1: 00fafa90bda066139c60920b3913bc3f19a00df3sha256: 9a1962e7a4d216c247b6e58a45dfa405127b93d1f489afab6bdeaa9fecce9aabsha512: 05ec1728bf34ff413724f5f65e0d768a327ecfc3bf1f2a8ea885ad3d1df5f06635f3dc5f0aa082e58b66b17fe450d1946d96ffbf62e9ff91e752327299b1b8bdssdeep: 196608:uCptntVvXeaCQvzlesm+ZJuBpZJJm3Ed:uyvOvQvzlC+ZJuBpZJJGEtype: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.InternalName: UIMgrBroker.exeFileVersion: 10.0.17134.1 (WinBuild.160101.0800)CompanyName: Microsoft CorporationProductName: Microsoftxae Windowsxae Operating SystemProductVersion: 10.0.17134.1FileDescription: Microsoft UIManager BrokerOriginalFilename: UIMgrBroker.exeTranslation: 0x0409 0x04b0

Trojan.Win32.Miner also known as:

FireEye Generic.mg.37bd2acae3abad01
Qihoo-360 Win32/Trojan.f11
Malwarebytes RiskWare.BitCoinMiner
AegisLab Trojan.Win32.Miner.4!c
K7GW Adware ( 0055631f1 )
K7AntiVirus Adware ( 0055631f1 )
TrendMicro TROJ_GEN.R002C0PC120
Cyren W64/Trojan.SBOF-2451
Symantec Trojan.Gen.MBT
TrendMicro-HouseCall TROJ_GEN.R002C0PC120
ClamAV Win.Coinminer.Generic-7151250-0
GData Win64.Trojan.Agent.5VP7KV
Kaspersky HEUR:Trojan.Win32.Miner.gen
Alibaba Trojan:Win32/Miners.c990e56b
NANO-Antivirus Trojan.Win64.Miner.hddlde
APEX Malicious
Rising Trojan.Miner!8.EA1 (CLOUD)
Sophos Generic PUA AA (PUA)
Comodo Malware@#3t7lk2v3g5rap
F-Secure Heuristic.HEUR/AGEN.1045823
DrWeb Tool.BtcMine.2110
Zillya Trojan.Miner.Win32.9647
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win64.CoinMiner.vh
Trapmine malicious.moderate.ml.score
Jiangmin Trojan.Miner.kvn
Avira HEUR/AGEN.1045823
Endgame malicious (high confidence)
ZoneAlarm HEUR:Trojan.Win32.Miner.gen
Microsoft PUA:Win32/CoinMiner
AhnLab-V3 Trojan/Win64.CoinMiner.R299388
Acronis suspicious
McAfee W64/CoinMiner
VBA32 Trojan.Miner
Cylance Unsafe
Panda Trj/CI.A
ESET-NOD32 a variant of Win64/CoinMiner.PO potentially unwanted
Ikarus PUA.CoinMiner
Fortinet W64/CryptoMiner.L!tr
AVG Win32:HarHarMiner-A [Trj]
Cybereason malicious.0bda06
Avast Win32:HarHarMiner-A [Trj]

How to remove Trojan.Win32.Miner?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.1560801952 malicious file

The Malware.AI.1560801952 is considered dangerous by lots of security experts. When this infection is active,…

28 mins ago

Malware.AI.3778280684 removal tips

The Malware.AI.3778280684 is considered dangerous by lots of security experts. When this infection is active,…

33 mins ago

Should I remove “Jalapeno.777”?

The Jalapeno.777 is considered dangerous by lots of security experts. When this infection is active,…

33 mins ago

MSIL/Kryptik.ALMH (file analysis)

The MSIL/Kryptik.ALMH is considered dangerous by lots of security experts. When this infection is active,…

38 mins ago

Should I remove “Trojan.Win32.Agent.xbmkrx”?

The Trojan.Win32.Agent.xbmkrx is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Tedy.179306 removal guide

The Tedy.179306 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago