Trojan

Trojan.Win64.Miner.pef removal tips

Malware Removal

The Trojan.Win64.Miner.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Miner.pef virus can do?

  • Communicates with IPs located across a large number of unique countries
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Multiple direct IP connections
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup

How to determine Trojan.Win64.Miner.pef?


File Info:

name: BC137A2CB68F8A832E6E.mlw
path: /opt/CAPEv2/storage/binaries/112eb4002eb203f69aa678275b4590e09c33b9228198b7f0fab16711d4797ee8
crc32: B17BDCFF
md5: bc137a2cb68f8a832e6e26db83c25cdf
sha1: e7c0d4fe78fe8e413ae5445b5d6245487c8aeedc
sha256: 112eb4002eb203f69aa678275b4590e09c33b9228198b7f0fab16711d4797ee8
sha512: 7c04fb0057f07312390fc302d6910f44335b67edb3488d4e11784ef786c1cde19bde1893321e9a9e0ce771e70110243e8d6f183d5bcff3588275165849e37632
ssdeep: 98304:EmJm/tFE4+DaC++U7ldouVbwmvPVlmAqyrw6EFGIgBf/tDE1U7TBDYMxuiAMGCmY:EPtndoK/3VlmkUwjZfBDYMxuD54X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE8633A3EBA492B2CAD164B14467C737AC366B08B72085C7C7FD283118368D0D77AF65
sha3_384: 632be8c87ba573aefe95d809250df03eb2d4784b679c926d699dfff366ae33cdc6517cb5303621ee56b0a66d58517781
ep_bytes: 6808050000680000000068acb24500e8
timestamp: 2020-05-20 10:06:32

Version Info:

ProductName: Microsoft? Windows? Operating System
ProductVersion: 10.1.17234.556
FileDescription: Host Process for Windows Services
LegalCopyright: ? Microsoft Corporation. All rights reserved.
Translation: 0x0000 0x04b0

Trojan.Win64.Miner.pef also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.14921
FireEyeGeneric.mg.bc137a2cb68f8a83
CAT-QuickHealTrojan.GenericPMF.S15920341
McAfeeGenericRXPC-ZJ!BC137A2CB68F
MalwarebytesMalware.AI.498111797
ZillyaTrojan.Scar.Win32.137027
K7AntiVirusTrojan ( 0055fd4b1 )
K7GWTrojan ( 0055fd4b1 )
Cybereasonmalicious.cb68f8
CyrenW32/S-4e460bf2!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ABMT
APEXMalicious
KasperskyHEUR:Trojan.Win64.Miner.pef
BitDefenderGen:Variant.Doina.14921
NANO-AntivirusTrojan.Win32.Mlw.hwpwiv
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10cf876c
Ad-AwareGen:Variant.Doina.14921
EmsisoftGen:Variant.Doina.14921 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Scar.rlw
eGambitUnsafe.AI_Score_96%
AviraHEUR/AGEN.1137863
Antiy-AVLTrojan/Generic.ASMalwS.30AAAA0
MicrosoftTrojan:Win32/Miner.KA!MTB
GDataGen:Variant.Doina.14921
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R346308
BitDefenderThetaGen:NN.ZexaF.34294.@x3@aC8hKtpi
ALYacGen:Variant.Doina.14921
MAXmalware (ai score=82)
VBA32BScope.Trojan.MulDrop
CylanceUnsafe
RisingTrojan.CoinMiner!1.CF9A (CLASSIC)
YandexTrojan.Agent!OTGcyG/nmKQ
IkarusTrojan.Win32.Agent
FortinetW32/CoinMiner.ED58!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.Win64.Miner.pef?

Trojan.Win64.Miner.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment