Malware

Win32/CoinMiner.FS potentially unwanted malicious file

Malware Removal

The Win32/CoinMiner.FS potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/CoinMiner.FS potentially unwanted virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 0.0.0.0:8800, :0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32/CoinMiner.FS potentially unwanted?


File Info:

name: 63AD656F3D342AD0FB9C.mlw
path: /opt/CAPEv2/storage/binaries/204412ef9238b28f70742ca83664a99fb6984945433d16ed20c0939363b83889
crc32: DD72F09D
md5: 63ad656f3d342ad0fb9c1414abdc08d3
sha1: c3d811f590b3bb63f04c69f66d5f3526ea784a6b
sha256: 204412ef9238b28f70742ca83664a99fb6984945433d16ed20c0939363b83889
sha512: 4762afb79d085d056d9fd214232b5a189462e47ae0fbf7b42b88dad77508867bbc8d7543b5a411f23c11445686ec9597c955a0b84bc924c0ed8f3a2e1f5c555d
ssdeep: 49152:vgwRDsggKLr9KcwDn0OY25+G4WpibvARLJkCTD49fYLW7m5Asv:vgwRwggK/o/QOY25+G44iDARLJy9fyg6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB8522F1BBE1A8B6E02021737454B23D33E7EE1D8F295493D39AF51A3871AD160B560B
sha3_384: a4e8a4caf49246760f63348ea18b47236b4c18c54dda16035cdc8ae12c20baa8609dde7d9b339bf5faa5f1f870e43db6
ep_bytes: 558bec6aff6870c4410068c095410064
timestamp: 2012-12-31 00:38:51

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

Win32/CoinMiner.FS potentially unwanted also known as:

LionicRiskware.Win32.CoinMiner.1!c
McAfeeArtemis!63AD656F3D34
CylanceUnsafe
SangforPUP.Win32.Agent.KPMBWG
K7AntiVirusAdware ( 00524e301 )
K7GWAdware ( 00524e301 )
CyrenW32/Trojan.NFBH-1782
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/CoinMiner.FS potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
NANO-AntivirusRiskware.Win32.Miner.frpfae
SophosGeneric Reputation PUA (PUA)
ComodoMalware@#7unccwk0c4c6
TrendMicroCoinminer_ETHEREUM.SM
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
GDataWin32.Application.Agent.KPMBWG
Antiy-AVLTrojan/Generic.ASCommon.212
GridinsoftRansom.Win32.Gen.sa
ViRobotAdware.Miner.1770529
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4198781
VBA32BScope.Trojan.Wacatac
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallCoinminer_ETHEREUM.SM
RisingTrojan.Generic@AI.84 (RDML:JR3jBZ0lVLOJnTx3n2GfWg)
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Miner
AVGWin32:Malware-gen

How to remove Win32/CoinMiner.FS potentially unwanted?

Win32/CoinMiner.FS potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment