Trojan

Trojan:Win32/CoinMiner.C!rfn removal

Malware Removal

The Trojan:Win32/CoinMiner.C!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CoinMiner.C!rfn virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Trojan:Win32/CoinMiner.C!rfn?


File Info:

crc32: C4451EA3
md5: 42514c189b79b97f33e92583c2db4c0a
name: 64.exe
sha1: 318735e59d220f143c70e76e6d35627505dde354
sha256: 9102fc80e0f3d9157a2f00ad52a7c8ed17622d2e2ff4e4b37e2b223503fbf6ce
sha512: 34a30a12f1aea285d94301326a18c0d3b9d07b1ab1c4ec262df754467c1f4a13137a239d77ee0fe7103e33e6540838fd4a79eb62964cba8e48ed1257f34aaae6
ssdeep: 6144:Dh75pAtYMSF+nvXqv/PtRJgE3yQ0hqISPYH48SZGMILF1MKRVAgQK0qeM4bOwft:ZTSYMY+nvgPtRGE3B0PSPYH48SZG1F1
type: PE32+ executable (console) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016-2019 xmrig.com
FileVersion: 2.13.0
CompanyName: www.xmrig.com
ProductName: XMRig
ProductVersion: 2.13.0
FileDescription: XMRig CPU miner
OriginalFilename: xmrig.exe
Translation: 0x0000 0x04b0

Trojan:Win32/CoinMiner.C!rfn also known as:

MicroWorld-eScanGeneric.Application.CoinMiner.1.A11194AF
FireEyeGeneric.mg.42514c189b79b97f
Qihoo-360Win32/Virus.RiskTool.416
McAfeeRDN/Generic.gmq
CylanceUnsafe
ZillyaTrojan.Miner.Win32.8838
SangforMalware
K7AntiVirusAdware ( 00523bf51 )
BitDefenderGeneric.Application.CoinMiner.1.A11194AF
K7GWAdware ( 00523bf51 )
Invinceaheuristic
APEXMalicious
Paloaltogeneric.ml
GDataGeneric.Application.CoinMiner.1.A11194AF
Kasperskynot-a-virus:RiskTool.Win32.Miner.bwg
AlibabaTrojan:Win32/CoinMiner.ali1004001
NANO-AntivirusRiskware.Win64.Miner.gdppbh
ViRobotAdware.Coinminer.382464
RisingTrojan.Win32/64.XMR-Miner!1.ADCC (CLOUD)
Ad-AwareGeneric.Application.CoinMiner.1.A11194AF
EmsisoftGeneric.Application.CoinMiner.1.A11194AF (B)
ComodoMalware@#2nutnfwl53w08
F-SecureTrojan.TR/AD.CoinMiner.rddnr
DrWebTrojan.BtcMine.3387
VIPRETrojan.Win32.Generic!BT
TrendMicroCoinminer.Win64.TOOLXMR.SMA
McAfee-GW-EditionBehavesLike.Win64.Downloader.fc
Trapminemalicious.moderate.ml.score
SophosXMRig Miner (PUA)
SentinelOneDFI – Malicious PE
CyrenW64/Application.UZBR-8734
JiangminRiskTool.Miner.co
WebrootBitcoinminer.Gen
AviraTR/AD.CoinMiner.rddnr
MAXmalware (ai score=82)
Antiy-AVLRiskWare[RiskTool]/Win32.Miner
Endgamemalicious (moderate confidence)
ArcabitGeneric.Application.CoinMiner.1.A11194AF
SUPERAntiSpywareTrojan.Agent/Gen-Midie
ZoneAlarmnot-a-virus:RiskTool.Win32.Miner.bwg
MicrosoftTrojan:Win32/CoinMiner.C!rfn
AhnLab-V3Unwanted/Win64.XMR-Miner.R294821
Acronissuspicious
ALYacTrojan.Agent.Miner
MalwarebytesRiskWare.BitCoinMiner
PandaTrj/CI.A
ESET-NOD32a variant of Win64/CoinMiner.DN potentially unwanted
TencentWin32.Trojan.Generic.Pall
IkarusTrojan.Win64.CoinMiner
eGambitUnsafe.AI_Score_91%
FortinetRiskware/Miner
AVGWin32:XMRigMiner-E [Trj]
Cybereasonmalicious.89b79b
AvastWin32:XMRigMiner-E [Trj]
MaxSecureTrojan.Malware.74630808.susgen

How to remove Trojan:Win32/CoinMiner.C!rfn?

Trojan:Win32/CoinMiner.C!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment