Trojan

Trojan:Win32/Coinminer.PA!MTB removal tips

Malware Removal

The Trojan:Win32/Coinminer.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Coinminer.PA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Empties the Recycle Bin, indicative of ransomware
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Coinminer.PA!MTB?


File Info:

crc32: EB30F4D0
md5: 67329d782c94c119a007bb2f8fac9f89
name: SQLAGENTIDC.exe
sha1: 34e66280a3732e2e72f88d7c6c2ea23ba6f93f10
sha256: 880aab9820b4ad950bfd5e311ba1d00f27c41734a9b1486733eba5ff30e7dde2
sha512: 1fb841b0e7e819d3fd74de423dc54da2a35f4ed994173aa92f36e88a138959671f5fb0a0dcb9846aa667e167d7a757d6015f87ab6317b952dfb581008b13df17
ssdeep: 12288:pAsjmBQyLmzkOlzPvm0Ad2X9l2QL5Lag+VcKYwU15vNO7l:pHjYmzkS7Nl245mg+owmNO7l
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2015 CHINA CITIC BANK.
InternalName: update.exe
FileVersion: 1.2.0.0720
CompanyName: x4e2dx4fe1x94f6x884c
Comments: x4e2dx4fe1x94f6x884cx7f51x94f6x4f34x4fa3
ProductName: update.exe
ProductVersion: 1.2.0.0720
FileDescription: x7f51x94f6x4f34x4fa3x5347x7ea7x7a0bx5e8f
OriginalFilename: update.exe
Translation: 0x0804 0x03a8

Trojan:Win32/Coinminer.PA!MTB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGeneric.Mulinex.DA25F523
FireEyeGeneric.mg.67329d782c94c119
CAT-QuickHealPUA.BitminRI.S9338387
CylanceUnsafe
K7AntiVirusTrojan ( 00561c1b1 )
BitDefenderGeneric.Mulinex.DA25F523
K7GWTrojan ( 00561c1b1 )
Cybereasonmalicious.82c94c
F-ProtW32/Trojan.CLL.gen!Eldorado
SymantecMiner.XMRig
APEXMalicious
AvastWin32:CoinMiner-M [Trj]
ClamAVWin.Malware.Midie-7357494-0
GDataGeneric.Mulinex.DA25F523
KasperskyTrojan-Downloader.Win32.Bitmin.xwy
Endgamemalicious (moderate confidence)
SophosTroj/Agent-BCPO
F-SecureHeuristic.HEUR/AGEN.1046199
DrWebTrojan.BtcMine.3404
ZillyaTrojan.CoinMiner.Win32.25455
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftGeneric.Mulinex.DA25F523 (B)
IkarusTrojan.Win32.CoinMiner
CyrenW32/Trojan.CLL.gen!Eldorado
JiangminTrojanDownloader.Bitmin.mz
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1046199
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=85)
Antiy-AVLTrojan[Downloader]/Win32.Upatre
MicrosoftTrojan:Win32/Coinminer.PA!MTB
ArcabitGeneric.Mulinex.DA25F523
ZoneAlarmTrojan-Downloader.Win32.Bitmin.xwy
AhnLab-V3Malware/Win32.RL_Coinminer.R328898
Acronissuspicious
VBA32BScope.Trojan.CMY3U
ALYacGeneric.Mulinex.DA25F523
Ad-AwareGeneric.Mulinex.DA25F523
MalwarebytesRiskWare.BitCoinMiner
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/CoinMiner.BUF
RisingBackdoor.Agent!1.B7E4 (RDMK:cmRtazrJjHMYpbCGO/JZDyHpOyxa)
YandexTrojan.CoinMiner!aW1qAi1rDo4
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQWare.A!tr
BitDefenderThetaGen:NN.ZexaF.34100.HmKfaWDBG0ej
AVGWin32:CoinMiner-M [Trj]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Trojan:Win32/Coinminer.PA!MTB?

Trojan:Win32/Coinminer.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment