Trojan

Trojan:Win32/CoinMiner.AC!rfn removal tips

Malware Removal

The Trojan:Win32/CoinMiner.AC!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CoinMiner.AC!rfn virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Anomalous binary characteristics

How to determine Trojan:Win32/CoinMiner.AC!rfn?


File Info:

crc32: BFF92033
md5: 8bc683c030807c9e7d4d860315ee92c9
name: 8BC683C030807C9E7D4D860315EE92C9.mlw
sha1: b146efdcefea908b3f8c94f39d5a11e492e0fe54
sha256: 3f66cf42b714dbf5746a4885398bcd2efb4b3f1569f6d83b5cc541dd9b477b16
sha512: 46931c5c761360aca9004d30ead08f5426a5d7725792553089e02386d13c2edb82eb889071d9e89d4157fea40ffe83125b06ef7b297313569418cea013b7c7c4
ssdeep: 49152:9Xz+r/MRc0tUgETcYJ+/yqOUw7Bpk5Q4c+mAE8JG:9Xz+r+urNJ+/pE74Tc+mL8w
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Smerfy
FileDescription: Smerfy 1.88 Installation
FileVersion: 1.88
Comments:
CompanyName: Smerfy
Translation: 0x0409 0x04e4

Trojan:Win32/CoinMiner.AC!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005241351 )
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.DownLoader23.43813
CynetMalicious (score: 99)
CylanceUnsafe
SangforTrojan.Win32.Generik.NGELPQW
K7GWTrojan ( 005241351 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NGELPQW
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.kqfd
NANO-AntivirusTrojan.Win32.Blocker.exittc
TencentWin32.Trojan.Blocker.Eehq
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.8bc683c030807c9e
JiangminTrojan.Blocker.idc
AviraTR/BAS.Samca.1423250
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/CoinMiner.AC!rfn
McAfeeArtemis!8BC683C03080
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetGenerik.NGELPQW!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOoA

How to remove Trojan:Win32/CoinMiner.AC!rfn?

Trojan:Win32/CoinMiner.AC!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment