Trojan

Trojan:Win32/CoinMiner.XI (file analysis)

Malware Removal

The Trojan:Win32/CoinMiner.XI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CoinMiner.XI virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/CoinMiner.XI?


File Info:

crc32: 9C77BA71
md5: 7820e8ed7caaa0b3aa9f79a7b0feed3a
name: 7820E8ED7CAAA0B3AA9F79A7B0FEED3A.mlw
sha1: e964001adf4b67571de59352212ab94b43af78d4
sha256: 17f3a3872d986e4f6d337e165fe8b9658fc70344b924cba25952a46a37e0c67e
sha512: f7a5777cb3b131dd18ffdadc30f80a36506ad973e187adb8b3be96dbf1a13947bf9aaa5d3c1be187e81eb558525a229b5268b3e853110e12a60424d3a1ff4eac
ssdeep: 98304:Tiz+1C+zdkZRD/XSUMUuRaheLUXMkId/Rb+49/b0:mz0zdkHPtuAheLUXZM/Xw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/CoinMiner.XI also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055b4a31 )
LionicTrojan.BAT.Miner.4!c
Elasticmalicious (high confidence)
DrWebTool.BtcMine.2110
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.42873734
CylanceUnsafe
SangforTrojan.Win32.Agent.gen
K7GWTrojan ( 0055b4a31 )
Cybereasonmalicious.d7caaa
CyrenW32/Risk.JOFN-3712
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Tool.Kmsauto-6988298-0
KasperskyTrojan.BAT.Miner.hj
BitDefenderTrojan.GenericKD.42873734
NANO-AntivirusTrojan.Win64.Miner.gfqtuh
MicroWorld-eScanTrojan.GenericKD.42873734
TencentBat.Trojan.Miner.Agku
Ad-AwareTrojan.GenericKD.42873734
SophosGeneric Reputation PUA (PUA)
ComodoMalware@#26kz73o3joa7j
VIPRETrojan.Win32.Generic!BT
TrendMicroCRCK_CRACK
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.7820e8ed7caaa0b3
EmsisoftTrojan.GenericKD.42873734 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Script.ahic
AviraHEUR/AGEN.1119227
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2CD7B6D
MicrosoftTrojan:Win32/CoinMiner.XI
GDataWin32.Application.CoinMiner.X
AhnLab-V3HackTool/Win.KMSAuto.R430157
McAfeeArtemis!7820E8ED7CAA
MAXmalware (ai score=85)
VBA32Trojan.Miner
MalwarebytesMalware.AI.3966286124
PandaTrj/CI.A
RisingHackTool.XMRMiner!1.C2EC (CLASSIC)
IkarusTrojan.Agent
FortinetRiskware/KMSAuto
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/CoinMiner.XI?

Trojan:Win32/CoinMiner.XI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment