Trojan

Trojan:Win64/Coinminer.RB!MTB removal

Malware Removal

The Trojan:Win64/Coinminer.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Coinminer.RB!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win64/Coinminer.RB!MTB?


File Info:

name: 95821D8EE492C45E5254.mlw
path: /opt/CAPEv2/storage/binaries/c0d9693c1c9d6ac29bf7e26d81b085e03b53593ad9640423c06d6b7610c330c0
crc32: AFAE25C7
md5: 95821d8ee492c45e5254ef3cbd04b173
sha1: 5f3c5aa4773b1df172d3e2e709e8ee036dd61063
sha256: c0d9693c1c9d6ac29bf7e26d81b085e03b53593ad9640423c06d6b7610c330c0
sha512: 6bbbce8bdccb646364ba35bc0959d6951528c56143ea4a901ad6a491465b8a0b1e83ee0ecc60d92eac962b9eac1cce90b3c2b3028963d28f3415e0af00779db7
ssdeep: 98304:d170mw+PtAaQ5IW0Wui1xsYiGgrYQMwZnzLZ/eG7KjS://3P1Q5d0G1xsYWrBzLVxKW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182263302B7D48072E1331B3526A59A265BBF7C901F385EEF438C656E5B375828F35B22
sha3_384: 3a5ec03bc8e4904fa3397cf954c37be17bc6c250b59a60fdda53043160c9a9e08f783ff79591ef9918981944c1948cb7
ep_bytes: e8c6040000e978feffffcccccccccccc
timestamp: 2023-09-17 15:25:15

Version Info:

0: [No Data]

Trojan:Win64/Coinminer.RB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Reflo.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.71052848
ClamAVWin.Packed.Babar-10012967-0
SkyhighBehavesLike.Win32.Generic.rc
McAfeeArtemis!95821D8EE492
Cylanceunsafe
ZillyaTrojan.Zenpak.Win32.21572
SangforTrojan.Win64.Kryptik.Vi24
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win64/Coinminer.d3d80083
ArcabitTrojan.Generic.D43C2E30
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Kryptik.EDF
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win64.Reflo.pef
BitDefenderTrojan.GenericKD.71052848
NANO-AntivirusTrojan.Win64.Inject5.kgmbop
AvastWin64:Evo-gen [Trj]
EmsisoftTrojan.GenericKD.71052848 (B)
F-SecureTrojan.TR/Kryptik.zbxbb
DrWebTrojan.Inject5.642
VIPRETrojan.GenericKD.71052848
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GoogleDetected
Antiy-AVLTrojan/Win64.GenKryptik
MicrosoftTrojan:Win64/Coinminer.RB!MTB
ZoneAlarmHEUR:Trojan.Win64.Reflo.pef
GDataTrojan.GenericKD.71052848
VaristW64/ABRisk.QAAD-8346
MAXmalware (ai score=84)
MalwarebytesTrojan.BitCoinMiner.Generic
TencentWin64.Trojan.Reflo.Uylw
IkarusTrojan.Win64.Krypt
FortinetW64/GenKryptik.GQCB!tr
AVGWin64:Evo-gen [Trj]
Cybereasonmalicious.4773b1
DeepInstinctMALICIOUS

How to remove Trojan:Win64/Coinminer.RB!MTB?

Trojan:Win64/Coinminer.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment