Trojan

Trojan:MSIL/CoinMiner.KA!bit removal guide

Malware Removal

The Trojan:MSIL/CoinMiner.KA!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/CoinMiner.KA!bit virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:MSIL/CoinMiner.KA!bit?


File Info:

crc32: EB4C68D0
md5: 964e2ebce5b31f7cfd8af7b4277b3e75
name: 964E2EBCE5B31F7CFD8AF7B4277B3E75.mlw
sha1: a877c4f811a7d35aa4533400b338dfa66793f1bb
sha256: 6addc6099433aa29013870ff0eed68dc04945c2b667a9e7dfe69aa3f60f7ee59
sha512: 329d2e799b7acf1afd4694034e79e2514b2af088d84a2eb6a842e6f5368a055a4f96537ef7f0eae3ac8a9d34364c250425916b867aa28e37035b408de571cc0e
ssdeep: 384:n82rvSFPZlH19GTXjdhDK5uujYcV6AUwJFZb:n8C6RPV9Ahe5fYcV6Dw9b
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 2.1.3.5
InternalName: LoaderBot.exe
FileVersion: 2.6.1.2
ProductVersion: 2.6.1.2
FileDescription:
OriginalFilename: LoaderBot.exe

Trojan:MSIL/CoinMiner.KA!bit also known as:

K7AntiVirusTrojan ( 005179cd1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.65376
CynetMalicious (score: 85)
CAT-QuickHealTrojan.Sigmal.S2323694
ALYacGen:Variant.MSILPerseus.107550
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win32.7293
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:MSIL/CoinMiner.ed5902b2
K7GWTrojan ( 005179cd1 )
Cybereasonmalicious.ce5b31
TrendMicroCoinminer_MINERBOT.SM-WIN32
CyrenW32/S-cf72f26b!Eldorado
SymantecTrojan.Coinbitminer
ESET-NOD32a variant of MSIL/CoinMiner.ACZ
APEXMalicious
AvastWin32:LoaderBotMiner-A [Trj]
ClamAVWin.Malware.Zusy-6994770-0
KasperskyHEUR:Trojan-Dropper.MSIL.Generic
BitDefenderGen:Variant.MSILPerseus.107550
NANO-AntivirusTrojan.Win32.CoinMiner.exeazg
SUPERAntiSpywareTrojan.Agent/Gen-Dynamer
MicroWorld-eScanGen:Variant.MSILPerseus.107550
TencentMsil.Trojan-dropper.Generic.Hsio
Ad-AwareGen:Variant.MSILPerseus.107550
ComodoTrojWare.MSIL.CoinMiner.ACZ@7iipdi
F-SecureTrojan.TR/ATRAPS.Gen
BitDefenderThetaGen:NN.ZemsilF.34186.bm0@aSU!bnk
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
FireEyeGeneric.mg.964e2ebce5b31f7c
SophosMal/Miner-J
SentinelOneDFI – Malicious PE
JiangminTrojanDropper.MSIL.anan
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan[Dropper]/MSIL.AGeneric
MicrosoftTrojan:MSIL/CoinMiner.KA!bit
ArcabitTrojan.MSILPerseus.D1A41E
AegisLabTrojan.MSIL.Generic.4!c
ZoneAlarmHEUR:Trojan-Dropper.MSIL.Generic
GDataGen:Variant.MSILPerseus.107550
AhnLab-V3Trojan/Win32.Tiggre.R218036
McAfeeGenericRXDK-DV!964E2EBCE5B3
MAXmalware (ai score=98)
VBA32Trojan.MSIL.gen.m
MalwarebytesTrojan.BitCoinMiner
PandaTrj/GdSda.A
TrendMicro-HouseCallCoinminer_MINERBOT.SM-WIN32
RisingDropper.Generic!8.35E (CLOUD)
IkarusTrojan.MSIL.CoinMiner
FortinetMSIL/CoinMiner.ACZ!tr
AVGWin32:LoaderBotMiner-A [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.bc3

How to remove Trojan:MSIL/CoinMiner.KA!bit?

Trojan:MSIL/CoinMiner.KA!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment