Malware

How to remove “Win32/CoinMiner.BV potentially unwanted”?

Malware Removal

The Win32/CoinMiner.BV potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/CoinMiner.BV potentially unwanted virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/CoinMiner.BV potentially unwanted?


File Info:

crc32: 0BE90178
md5: de1b79446534868ad5fcd7d8dd8e6156
name: cpuminer32.exe
sha1: 066eb87abf89219c1a26ec8a9a44d4319d217a33
sha256: ca5bc154abbc1a6a4eabdfb4734c72758dce29d26d7a7956095b19f201860feb
sha512: 71c0b3a00843e89978bb7189d9ea0351658b2eee60edaa303d8df9f9b452a82d2a7fde82038d41f122faac558f4f8ee800148cfaea6ae600ec5c36d549f5aca2
ssdeep: 49152:wvpqT27FCSzPPMx+wrj1wNic9gFQn8rDGRTko/gyz:wBqnAivqf/gyz
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: xa9 Kaspersky Labs. All rights reserved.
ProductVersion: 1.0.4.9
FileVersion: 1.0.4.9
OriginalFilename: Kaspersky Startup Security Scan.exe
CompanyName: Kaspersky Labs
Translation: 0x0409 0x04b0

Win32/CoinMiner.BV potentially unwanted also known as:

MicroWorld-eScanGen:Application.Heur2.aM1@bWOVmFhib
FireEyeGeneric.mg.de1b79446534868a
CylanceUnsafe
ZillyaTrojan.Snojan.Win32.329
K7AntiVirusUnwanted-Program ( 004d38111 )
BitDefenderGen:Application.Heur2.aM1@bWOVmFhib
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.465348
AvastWin32:Miner-BA [Trj]
GDataGen:Application.Heur2.aM1@bWOVmFhib
KasperskyTrojan.Win32.Snojan.hrd
NANO-AntivirusTrojan.Win32.Snojan.enhfuh
AegisLabTrojan.Win32.Generic.4!c
TencentMalware.Win32.Gencirc.114b4dfc
Endgamemalicious (high confidence)
ComodoMalware@#13p7zfs0x5m1j
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
EmsisoftGen:Application.Heur2.aM1@bWOVmFhib (B)
IkarusPUA.CoinMiner
MAXmalware (ai score=74)
ArcabitApplication.Heur2.E27639
ZoneAlarmTrojan.Win32.Snojan.hrd
MicrosoftPUA:Win32/CoinMiner
Ad-AwareGen:Application.Heur2.aM1@bWOVmFhib
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/CoinMiner.BV potentially unwanted
RisingTrojan.Snojan!8.E387 (CLOUD)
YandexRiskware.Agent!
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
FortinetRiskware/CoinMiner
AVGWin32:Miner-BA [Trj]
Qihoo-360Win32/Application.83b

How to remove Win32/CoinMiner.BV potentially unwanted?

Win32/CoinMiner.BV potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment