Trojan

Trojan:MSIL/CoinMiner.PS!bit removal tips

Malware Removal

The Trojan:MSIL/CoinMiner.PS!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/CoinMiner.PS!bit virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:MSIL/CoinMiner.PS!bit?


File Info:

crc32: 2F50A355
md5: 155d52148373b99ac9ced28ba12ee942
name: lo.exe
sha1: 85fd9e6f6364820bad5caf3fae77706ad59f9e58
sha256: a97662cfe394f1f13b11cb3e55e4bbf89453f2b2363ae0c9ccd44764f7f9503e
sha512: c9c27f2c108c37f6ed34a90d16ce695d0aeb9fe722fac5ac103d03ecccf1afd41c54b25a15b48267b1baa7d1b52034508a71b3c4ab53b3bebf2fbfb8ba261ecb
ssdeep: 6144:JBy5q9nlHVGgM1O0hyBQNgFbrcKJXJ3ew+TuhfKzsf/UkjzmsoB7WZGffoN:IK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: 34x432x430x4332x432x431x4303x433x433x432x433x4334x4322x433x4333x433113x4321x4304x430x43023214A23x4321x433x4303x433313x431x4332x4314311x4331AAx431x433x430x430x433x4333x4334x431x431x43322x433x431x43141x433414x433x43111x4332x433
Assembly Version: 4.3.6.6
InternalName: BQACAgIAAxkBAAIq8V4__3KKGkaRNm6tP5hXDyZr5GxnAALyBAAC2t7BSQNbuJxzGcwWGAQ.exe
FileVersion: 4.3.6.6
CompanyName: 12x4302x4313x4332x4322x431422x43022x432x430233x431424Ax43243A1x432x43014x4302344x4331x432213x431234Ax431x431x4332x4314x431x431x430x4322x43242431x432x431x43244Ax43321A2431x4332A2x4334x433
LegalTrademarks: x432x43131x432x431x43114x431x43033331x432214A3x4324x4311x4304x43311x433x4301x433x432x43341x430x430x4321x430A1x432x4312x433x4333x432x431x4332A12312x43311x430x4333x4334x432x431x4332x433x431Ax4324x431x4332x4304x432x432x4303x432x433
Comments: x431x431x433Ax43143321221x43334x433x4332A31x432x433x431123x430x43121x4304x4332x431x4331x432x431x431x432x433414x4332x431x4324x433x432x432411x432x431x431x430x432AA4x432x4304x430x432x432x430314x433x43244x4304x4331x431x430AAA2
ProductName: x4311134x432Ax432x433x431x43323414x430x43344x432214x433134x43111x4333x433x431x4321Ax433x431x430x43343Ax430x4302x431A41Ax431x4331x433A1x431AA21x432A3x432x433x430x4311211x4333Ax432x4331x433241x4312x431x4312
ProductVersion: 4.3.6.6
FileDescription: x4301x43122Ax433x4331441341x431x43321x4334x431x431x4304x430A2x431x43234x431x432A1x431x433x431x4331x4322x433x433x431x4323342234x431x43241x430x4323x4332x4331432x430x430x43231442x4324x430x433x432x430x4321Ax433x433x433x4324
OriginalFilename: BQACAgIAAxkBAAIq8V4__3KKGkaRNm6tP5hXDyZr5GxnAALyBAAC2t7BSQNbuJxzGcwWGAQ.exe

Trojan:MSIL/CoinMiner.PS!bit also known as:

MicroWorld-eScanGen:Variant.Razy.606522
FireEyeGeneric.mg.155d52148373b99a
Qihoo-360Generic/Trojan.5f5
ALYacGen:Variant.Razy.606522
SangforMalware
BitDefenderGen:Variant.Razy.606522
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.34084.Bu2@aqK!7ub
APEXMalicious
GDataGen:Variant.Razy.606522
KasperskyUDS:DangerousObject.Multi.Generic
Ad-AwareGen:Variant.Razy.606522
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.606522 (B)
IkarusTrojan.MSIL.Injector
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D9413A
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:MSIL/CoinMiner.PS!bit
Acronissuspicious
McAfeeArtemis!155D52148373
MAXmalware (ai score=82)
MalwarebytesSpyware.PredatorTheThief
ESET-NOD32a variant of MSIL/Injector.ULP
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetMSIL/Injector.ULP!tr
AVGFileRepMalware

How to remove Trojan:MSIL/CoinMiner.PS!bit?

Trojan:MSIL/CoinMiner.PS!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment