Trojan

What is “Trojan:Win64/CoinMiner.GB!MTB”?

Malware Removal

The Trojan:Win64/CoinMiner.GB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/CoinMiner.GB!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan:Win64/CoinMiner.GB!MTB?


File Info:

crc32: CE6DFD53
md5: 7da1dfc307c8fd8aa0e14bbb96b3097c
name: 7DA1DFC307C8FD8AA0E14BBB96B3097C.mlw
sha1: c0e1c432cc613ac3ff551e6bf737268046a97ca2
sha256: 9aab68986f17006282cd459afda04d1764bdaaf7db61fb0613c373e39012bd7a
sha512: 840c81ab989b8b01dc4fd4023fa11c78a91864b65e2e1f703dbab0d7474470bdeb6a3d4f9d3400c7e894c3ce4e15a3ae8af39bccaad388754ab96c8eeef53eeb
ssdeep: 49152:UtV0eHhJwesK4YmaUMFH7vuVSkiXlY53456+3ez+:UJHheesKaazFWVo2534NO
type: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 2017 Google Inc. All rights reserved.
Assembly Version: 0.0.0.0
InternalName: x410x432.exe
FileVersion: 70.0.3538.110
CompanyName: Google Inc.
Comments: Google Chrome
ProductName: Google Chrome
ProductVersion: 70.0.3538.110
FileDescription: chrome.exe
OriginalFilename: x410x432.exe

Trojan:Win64/CoinMiner.GB!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDropNET.38
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.427541
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.2cc613
CyrenW64/MSIL_Troj.BCG.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/CoinMiner.BIP
APEXMalicious
AvastWin64:CoinminerX-gen [Trj]
ClamAVWin.Trojan.CoinMiner-9851722-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.427541
MicroWorld-eScanGen:Variant.Bulz.427541
Ad-AwareGen:Variant.Bulz.427541
SophosML/PE-A
McAfee-GW-EditionGenericRXOG-SA!7DA1DFC307C8
FireEyeGeneric.mg.7da1dfc307c8fd8a
EmsisoftGen:Variant.Bulz.427541 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1142184
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win64/CoinMiner.GB!MTB
GDataGen:Variant.Bulz.427541
AhnLab-V3Trojan/Win.Generic.C4451286
McAfeeGenericRXOG-SA!7DA1DFC307C8
MAXmalware (ai score=87)
MalwarebytesTrojan.BitCoinMiner
RisingTrojan.FakeChrome!1.9C7B (CLASSIC)
IkarusTrojan.MSIL.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.BIP!tr
AVGWin64:CoinminerX-gen [Trj]

How to remove Trojan:Win64/CoinMiner.GB!MTB?

Trojan:Win64/CoinMiner.GB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment