Malware

Win32/CoinMiner.BA potentially unwanted removal

Malware Removal

The Win32/CoinMiner.BA potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/CoinMiner.BA potentially unwanted virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/CoinMiner.BA potentially unwanted?


File Info:

name: 53606C919069B87BAEE2.mlw
path: /opt/CAPEv2/storage/binaries/a53d4b2df94c91a27cdd17cc5a2d514dc1b6bcf695dbf8de895707ea4f29ead8
crc32: B1343BF9
md5: 53606c919069b87baee24e990ec79060
sha1: c720b22f61388b2230ee05fda83ee3d51922028f
sha256: a53d4b2df94c91a27cdd17cc5a2d514dc1b6bcf695dbf8de895707ea4f29ead8
sha512: b5a0c65a3447546a14edda2b15784ebefe85d8361704eff7d23d009222c206721e5f302fdb875e5858f383c14fa39ea60ecdd96625ca354da418ab34da40b3e1
ssdeep: 24576:eUDQM4I7ftpJeAGvhl4rVu+YesegShI/0MD93Pkcahn6kcgNfPFy:wRI7ShlGufesegSi5D938ca9JcgN3w
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FE253958E64BA4F1DD27083042DFE27F0A71AE21C432DEAAFF5C7A49F933DA21615215
sha3_384: 03b6dc2794ae078b73d5d0877dbb2d7b9ec0ffd04e081d686afe0718b2f7e8666603d6356e77f3bbb09b88b5cc9e531f
ep_bytes: 83ec1cc7042401000000ff15a0965100
timestamp: 2013-09-13 11:50:52

Version Info:

0: [No Data]

Win32/CoinMiner.BA potentially unwanted also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.53606c919069b87b
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.57713
K7AntiVirusTrojan ( 0053a0551 )
AlibabaRiskWare:Win32/Miners.f2255f03
K7GWTrojan ( 0053a0551 )
Cybereasonmalicious.f61388
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.BA potentially unwanted
Kasperskynot-a-virus:RiskTool.Win32.BitCoinMiner.mxt
NANO-AntivirusRiskware.Win32.BtcMine.csvmtb
AvastWin32:BitCoinMiner-JU [Trj]
SophosBitcoin Miner (PUA)
ComodoMalware@#3njfj9fa4qalo
DrWebTool.BtcMine.143
VIPRETrojan.Win32.CoinMiner.ba (v)
McAfee-GW-EditionBehavesLike.Win32.PUP.dh
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gbui
WebrootW32.Trojan.Gen
AviraPUA/CoinMiner.Gen
Antiy-AVLTrojan/Generic.ASMalwS.F74E0C
McAfeeArtemis!53606C919069
MalwarebytesPUP.Optional.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R002H0CF321
RisingHackTool.CoinMiner!1.CA68 (CLASSIC)
YandexTrojan.Graftor!GbZ34Q2cL84
IkarusTrojan.Crypt
FortinetRiskware/CoinMiner
AVGWin32:BitCoinMiner-JU [Trj]

How to remove Win32/CoinMiner.BA potentially unwanted?

Win32/CoinMiner.BA potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment