Trojan

What is “Trojan:BAT/CoinMiner.A”?

Malware Removal

The Trojan:BAT/CoinMiner.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:BAT/CoinMiner.A virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:BAT/CoinMiner.A?


File Info:

crc32: D2404821
md5: 3a8d2fff9f9ec31add338d254c6e3662
name: 3A8D2FFF9F9EC31ADD338D254C6E3662.mlw
sha1: 863d3333ae61a6079fa8edf724b7741eeb269c2b
sha256: b77af987239f2bfa54092eafcb261d3ae25382a15acf151a980452680d2b2b15
sha512: 48a01103f0d16b42ea4a1e5c83b711ada9f609fb8ebe7ce309910854b049a58a7edc2325bc977663a2c417aa55c38ffce8ee9fbd408e5c37a8c3c0da662c2b32
ssdeep: 6144:0/fAhvV6B8ErzPZp5wdz753RSJT+tLFS9UHQH:QfAv6B8azBwdQT+t0SHg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:BAT/CoinMiner.A also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053fd3e1 )
LionicTrojan.Win32.Bsymem.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.56837
MicroWorld-eScanTrojan.Miner.BG
ALYacTrojan.Miner.BG
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:BAT/CoinMiner.1c0d56b3
K7GWTrojan ( 0053fd3e1 )
Cybereasonmalicious.f9f9ec
CyrenW32/Downloader.APOX-9336
SymantecTrojan.Gen.2
ESET-NOD32BAT/CoinMiner.ALT
APEXMalicious
AvastSFX:Agent-E [Trj]
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Bsymem.blm
BitDefenderTrojan.Miner.BG
NANO-AntivirusTrojan.Win32.Bsymem.fjpmmo
TencentWin32.Trojan.Bsymem.Llrp
Ad-AwareTrojan.Miner.BG
SophosMal/Generic-S
ComodoMalware@#1yfqq471oit93
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeTrojan.Miner.BG
EmsisoftTrojan.Miner.BG (B)
WebrootW32.Trojan.Uztuby
AviraTR/CoinMiner.pxvmd
MicrosoftTrojan:BAT/CoinMiner.A
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataTrojan.Miner.BG
AhnLab-V3Malware/Gen.Generic.C2789108
McAfeeArtemis!3A8D2FFF9F9E
MAXmalware (ai score=100)
PandaTrj/CI.A
IkarusTrojan.BAT.CoinMiner
FortinetW32/Bsymem.ALT!tr
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml

How to remove Trojan:BAT/CoinMiner.A?

Trojan:BAT/CoinMiner.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment