Trojan

Trojan.Win64.Miner.iaj removal guide

Malware Removal

The Trojan.Win64.Miner.iaj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Miner.iaj virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win64.Miner.iaj?


File Info:

name: BB65AE9AC11289CA88DC.mlw
path: /opt/CAPEv2/storage/binaries/e120cd91dd3a239658ad1792a720515214f8b33aad815d166303267df15eb26c
crc32: 56B9A61B
md5: bb65ae9ac11289ca88dc945b6ef9921b
sha1: 69c29c3b2197cf24c3540b5971ccbe9a97452952
sha256: e120cd91dd3a239658ad1792a720515214f8b33aad815d166303267df15eb26c
sha512: c4db067630bfda003097042ca4ebfc166f62f6d4683d724923443f3b0bc6c039ae422ae6f74127bc1ec06014b2304739b55ec38e106a0ef5302361bad8708fb4
ssdeep: 49152:2fRRudNFVngnIufe+B3xHnmYwsE7CHoEMY5vf7hYg:2fwfnmIwe+BhfYpb61d
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1B2B5337EC3608FB9D00A8379776B1AFD461329D06D8CE2867578E90D2D1BD3E68885F4
sha3_384: 1cd9aab611b3d122ec7b15e92eaff67765ad6ff15651d8e913d3c8352b67c15ca5af7d4d681e4c705a1b94a77997e492
ep_bytes: e98d5c0400e94f5e0400b5ef4cc5d54c
timestamp: 2018-04-22 08:30:53

Version Info:

0: [No Data]

Trojan.Win64.Miner.iaj also known as:

LionicTrojan.Win32.Miner.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.419015
FireEyeGeneric.mg.bb65ae9ac11289ca
ALYacGen:Variant.Bulz.419015
CylanceUnsafe
ZillyaTrojan.Miner.Win64.1133
SangforCoinMiner.Win64.Miner.iaj
AlibabaTrojan:Win64/Miner.5f39d1c3
Cybereasonmalicious.b2197c
CyrenW64/S-dd50cf81!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win64/CoinMiner.QB potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0WJ621
Paloaltogeneric.ml
KasperskyTrojan.Win64.Miner.iaj
BitDefenderGen:Variant.Bulz.419015
NANO-AntivirusTrojan.Win64.CoinMiner.fjmjyn
AvastWin32:XMRigMiner-AE [Miner]
Ad-AwareGen:Variant.Bulz.419015
EmsisoftGen:Variant.Bulz.419015 (B)
ComodoMalware@#glupbh481ysx
TrendMicroTROJ_GEN.R002C0WJ621
McAfee-GW-EditionBehavesLike.Win64.Wanex.vc
SophosXMRig Miner (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bulz.419015
JiangminTrojan.Miner.qui
AviraPUA/CoinMiner.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.28B7B2F
ViRobotAdware.Coinminer.2348544.B
MicrosoftTrojan:Win32/Coinminer.SIB!MTB
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win64.XMR-Miner.R223760
Acronissuspicious
McAfeeArtemis!BB65AE9AC112
MalwarebytesMalware.AI.2874227652
APEXMalicious
TencentWin64.Trojan.Miner.Pgwj
YandexTrojan.GenAsa!lNMIIEh5gvU
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.DC
AVGWin32:XMRigMiner-AE [Miner]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Win64.Miner.iaj?

Trojan.Win64.Miner.iaj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment