Malware

Win32/CoinMiner.GB potentially unwanted removal guide

Malware Removal

The Win32/CoinMiner.GB potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/CoinMiner.GB potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/CoinMiner.GB potentially unwanted?


File Info:

name: 9D6F7738DD01CC7F945F.mlw
path: /opt/CAPEv2/storage/binaries/637816a6e92e5fae89a830e5cef7653f9017becdf34ef66644ffc829ee9806ba
crc32: 6DDF4B69
md5: 9d6f7738dd01cc7f945f795d17b6c634
sha1: b728c068f65c3ab0d64ee721baffe761718b674b
sha256: 637816a6e92e5fae89a830e5cef7653f9017becdf34ef66644ffc829ee9806ba
sha512: c07a8ad06ccc2633035d046aa359fdb2986d6c23b734996d0f506c365955f82830587a83387ff35e3fcc8dceb1dd78ca4110cb7c0cbf5df24b7142654d2baa82
ssdeep: 3072:aO0w5xU2JWmnJw4xW8L4WlIfW6g3EivJvny/Jl1Z3VmEHecyWKuMqqD+8bkgy375:aO3FWmndxlisDOnfaqqDSAKbQy
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12E64F78073E644A4F9735E3619B086258E7FBE616E62FE2E93C0151F45786E2C634F32
sha3_384: a6ff6754efeb8fd9dc2a16c8934c539157c499cb25ea6f9363c2820466ebba6b0146e74b4ba47409d55f071977bf21b6
ep_bytes: e842040000e987feffff558bec56ff75
timestamp: 2018-02-08 10:23:25

Version Info:

CompanyName: Idle Buddy Inc
FileDescription: IdleBuddy
FileVersion: 1.0.0.10
InternalName: IdleBuddy
LegalCopyright: Copyright (C) 2017
OriginalFilename: ibservice.exe
ProductName: IdleBuddy
ProductVersion: 1.0.0.10
Translation: 0x0409 0x04b0

Win32/CoinMiner.GB potentially unwanted also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.BitMiner.1!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.9d6f7738dd01cc7f
McAfeeGenericRXDZ-LX!9D6F7738DD01
CylanceUnsafe
ZillyaTool.BitCoinMiner.Win32.243
SangforPUP.Win32.BitCoinMiner.58
K7AntiVirusAdware ( 005268c51 )
AlibabaRiskWare:Win32/Miners.8fa47cfb
K7GWAdware ( 005268c51 )
Cybereasonmalicious.8dd01c
BitDefenderThetaGen:NN.ZexaF.34084.tC0@aS5XrwoO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.GB potentially unwanted
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
NANO-AntivirusRiskware.Win32.FileFinder.eyauwm
AvastFileRepMetagen [PUP]
TencentWin32.Risk.Bitminer.Hvtf
ComodoApplicUnwnt@#3aq80lhd7ruj6
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXDZ-LX!9D6F7738DD01
SophosGeneric PUA LH (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.ELEX.bsb
AviraADWARE/FileFinder.Gen7
MAXmalware (ai score=98)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 99)
MalwarebytesRiskWare.BitCoinMiner
APEXMalicious
YandexTrojan.GenAsa!1Cf47JwQlfU
IkarusPUA.CoinMiner
eGambitUnsafe.AI_Score_99%
FortinetRiskware/CoinMiner
AVGFileRepMetagen [PUP]
PandaTrj/GdSda.A

How to remove Win32/CoinMiner.GB potentially unwanted?

Win32/CoinMiner.GB potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment