Trojan

Trojan:MSIL/CoinMiner.S!MTB removal

Malware Removal

The Trojan:MSIL/CoinMiner.S!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/CoinMiner.S!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan:MSIL/CoinMiner.S!MTB?


File Info:

crc32: 813DD5E8
md5: c7e6056b257d3c9c8b22c51a94c3c796
name: readme.md
sha1: 833c11943664c396be9bc9f5e1b4da273c521715
sha256: 7a8578adde035689688ee889290bce0817b2c4df75a9bb7363bf6e4e627f4c2f
sha512: 17e972898f2cc022fd15b158692d6161bda5ce4cf87fc3703f38f230a6d072b2f34c50f5f3e617a94a6708e9f05978885bebdb77196dac2888cb66ae4af1cfc6
ssdeep: 98304:xCOWFZgT8/FdlYMwPFQdlVEP/bvVKtbKLm6rlWj3LXiL2VxwwseoV6M340qA2kI:odIkHGMteL/Wj3pwwHocy/qA2kIbut2
type: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: (c)2008-2018 CPUID. All rights reserved.
Assembly Version: 0.0.0.0
InternalName: readme.exe
FileVersion: 1.3.4.0
CompanyName: CPUID
Comments: HWMonitor
ProductName: CPUID Hardware Monitor
ProductVersion: 1.3.4.0
FileDescription: HWMonitor.exe
OriginalFilename: readme.exe

Trojan:MSIL/CoinMiner.S!MTB also known as:

DrWebTrojan.DownLoader33.18414
MicroWorld-eScanTrojan.GenericKD.42853678
McAfeeArtemis!C7E6056B257D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055628f1 )
BitDefenderTrojan.GenericKD.42853678
K7GWTrojan ( 0055628f1 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
TrendMicro-HouseCallTROJ_GEN.R002C0DCG20
AvastWin64:Trojan-gen
ClamAVWin.Packed.Razy-6862374-0
GDataTrojan.GenericKD.42853678
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/CoinMiner.e2286fa2
TencentMsil.Trojan.Coinminer.Tbik
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42853678 (B)
F-SecureHeuristic.HEUR/AGEN.1041868
TrendMicroTROJ_GEN.R002C0DCG20
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.c7e6056b257d3c9c
SophosMal/Kryptik-DO
IkarusTrojan.MSIL.CoinMiner
CyrenW64/Trojan.GJDZ-0746
AviraHEUR/AGEN.1041868
MAXmalware (ai score=87)
Antiy-AVLTrojan/MSIL.CoinMiner
MicrosoftTrojan:MSIL/CoinMiner.S!MTB
ArcabitTrojan.Generic.D28DE52E
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.RL_Generic.C3574602
Acronissuspicious
ALYacTrojan.GenericKD.42853678
Ad-AwareTrojan.GenericKD.42853678
APEXMalicious
ESET-NOD32a variant of MSIL/CoinMiner.BBF
SentinelOneDFI – Malicious PE
FortinetMSIL/CoinMiner.AXX!tr
WebrootW32.Trojan.Gen
AVGWin64:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:MSIL/CoinMiner.S!MTB?

Trojan:MSIL/CoinMiner.S!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment