Trojan

Trojan:Win32/CoinMiner!rfn removal tips

Malware Removal

The Trojan:Win32/CoinMiner!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CoinMiner!rfn virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan:Win32/CoinMiner!rfn?


File Info:

crc32: 27585375
md5: fbbcf1e9501234d6661a0c9ae6dc01c9
name: IMG001.scr
sha1: 1ca9759a324159f331e79ea6871ad62040521b41
sha256: d9901b16a93aad709947524379d572a7a7bf8e2741e27a1112c95977d4a6ea8c
sha512: 027e5ea6d92955b87439f61704de5b3e21c7a8e0a95327868951968e4f5cbed59cf1e803ac9adb2c9cf577db7a2f6fd4383b7384d57a78596cfb2ff020907140
ssdeep: 98304:M5VPnq1y5tQOM33ZNqCtBixHl54Oyjes1Ro6:2VPq1yLanrqTr43eON
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan:Win32/CoinMiner!rfn also known as:

BkavW32.BitcoinMinerAT.Trojan
MicroWorld-eScanTrojan.GenericKD.3498132
CAT-QuickHealTrojan.CoinMiner
McAfeeTrojan-CoinMiner
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004da88f1 )
BitDefenderTrojan.GenericKD.3498132
K7GWTrojan ( 004da88f1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroWORM_COINMINER.QA
BaiduMulti.Threats.InArchive
CyrenW32/Adware.DEZV-3749
SymantecTrojan.Coinbitminer
ESET-NOD32NSIS/CoinMiner.K
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Coinminer-6622864-0
KasperskyTrojan.NSIS.Agent.pf
AlibabaTrojan:Win32/CoinMiner.62842592
NANO-AntivirusTrojan.Win32.BitCoinMiner.ddjqfi
SUPERAntiSpywareHack.Tool/Gen-BitCoinMiner
TencentWin32.Trojan.Fakedoc.Auto
Ad-AwareTrojan.GenericKD.3498132
EmsisoftTrojan.GenericKD.3498132 (B)
ComodoMalware@#3sedq8onoin2s
F-SecureTrojan.TR/BitCoinMiner.fra
DrWebTrojan.BtcMine.1393
ZillyaAdware.Solimba.Win32.3282
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Mytob.wc
FortinetW32/CoinMiner.K!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fbbcf1e9501234d6
SophosMal/Miner-C
SentinelOneDFI – Malicious PE
F-ProtW32/Adware.ALRW
JiangminTrojanDownloader.VBS.qf
WebrootW32.Bitcoin.Miner
MAXmalware (ai score=100)
Antiy-AVLRiskWare[RiskTool]/Win32.BitCoinMiner.xou
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D356094
ViRobotDropper.S.BitCoinMiner.3552168
ZoneAlarmTrojan.NSIS.Agent.pf
MicrosoftTrojan:Win32/CoinMiner!rfn
AhnLab-V3Trojan/Win32.CoinMiner.R174018
Acronissuspicious
VBA32Trojan.Agent
ALYacMisc.Riskware.BitCoinMiner
PandaTrj/CI.A
TrendMicro-HouseCallWORM_COINMINER.QA
RisingMalware.Undefined!8.C (CLOUD)
YandexRiskware.Agent!
IkarusTrojan-PSW.Win32.Tepfer
eGambitUnsafe.AI_Score_100%
GDataTrojan.GenericKD.3498132
BitDefenderThetaAI:Packer.129981981F
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.950123
AvastScript:SNH-gen [Trj]
Qihoo-360Trojan.Generic

How to remove Trojan:Win32/CoinMiner!rfn?

Trojan:Win32/CoinMiner!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment