Malware

Should I remove “Win32/CoinMiner.BII”?

Malware Removal

The Win32/CoinMiner.BII is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/CoinMiner.BII virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/CoinMiner.BII?


File Info:

crc32: A83950D7
md5: 1689b5156472dbe028b8133daee01a31
name: upload_file
sha1: c2e92166dde2fbd462a5f3e9a38ce70781b58ec2
sha256: c74b83b05ce867ea4de4ed3cf58b11f02e061c5efd0b0f2b4ea5c59ca3a0eb47
sha512: 4d64141375c304f0769cdaa2cb4126f2f105f28f1b98d028ba8473372ce8c8509afcbc02d0b8b1d64d7c0207d6b3c09dfc5b2a94a94ba1d3f31f075c53a9377d
ssdeep: 12288:IU4Rt6vbGXOMdkFH+mS5x/Cm6gcvwnE6RS:uDNXvkFHlcxabUbRS
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, RAR self-extracting archive

Version Info:

0: [No Data]

Win32/CoinMiner.BII also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34383338
FireEyeGeneric.mg.1689b5156472dbe0
CAT-QuickHealTrojan.Wacatac
McAfeeGenericRXKU-NX!1689B5156472
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.lCIq
K7AntiVirusTrojan ( 0053f0a61 )
BitDefenderTrojan.GenericKD.34383338
K7GWTrojan ( 0053f0a61 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTROJ_GEN.R002C0CHI20
SymantecSMG.Heur!gen
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Ursu-7486622-0
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/CoinMiner.5499e53d
Ad-AwareTrojan.GenericKD.34383338
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1135107
DrWebProgram.SrvAny
Invinceaheuristic
SophosMal/Generic-S
IkarusTrojan.Win32.CoinMiner
JiangminTrojan/Agent.hghn
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1135107
MAXmalware (ai score=85)
Antiy-AVLTrojan[Downloader]/BAT.WGet
MicrosoftTrojan:Win64/CoinMiner
ArcabitTrojan.Generic.D20CA5EA
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.Agent.PZTRBF
CynetMalicious (score: 90)
ESET-NOD32Win32/CoinMiner.BII
ALYacTrojan.GenericKD.34383338
VBA32Trojan.Miner
TrendMicro-HouseCallTROJ_GEN.R002C0CHI20
TencentWin32.Trojan.Trojan.Dygv
FortinetRiskware/PerfectAutomation
AVGWin32:Trojan-gen
Cybereasonmalicious.6dde2f
AvastWin32:Trojan-gen
Qihoo-360Generic/HEUR/QVM11.1.5877.Malware.Gen

How to remove Win32/CoinMiner.BII?

Win32/CoinMiner.BII removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment