Categories: Malware

Win32/CoinMiner.IF potentially unwanted removal

The Win32/CoinMiner.IF potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/CoinMiner.IF potentially unwanted virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (766 unique times)
  • Starts servers listening on 0.0.0.0:19490
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Uses suspicious command line tools or Windows utilities

Related domains:

gulf.moneroocean.stream

How to determine Win32/CoinMiner.IF potentially unwanted?


File Info:

crc32: 9B54DE9Cmd5: 3239531f214dfc335fd8554192f00e37name: spread.txtsha1: 6bcdd7b71e79fe442b5c54dd64f2ed15bedf89e7sha256: 94f0e2aa41e1703e37341cba0601441b2d9fa2e11615cad81ba5c93042c8f58csha512: 9949254b78f98efc76f7310870d146b39c1a7faee6e3fe913f045267c3dd496b14c7b5eb3002180c3bf47f5b12932416ada78fb46cf77f312cabe898c8a7d994ssdeep: 196608:qx8rhDynXe6tVcjzQsYRgj5mvQqLVobzeYOwZWcwDN6r:NyXpvuc+zeYOGbwDNtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/CoinMiner.IF potentially unwanted also known as:

DrWeb Trojan.Equation.1
MicroWorld-eScan Trojan.GenericKD.31580441
CAT-QuickHeal Trojan.Detplock
McAfee Artemis!EDF1B2DE50AF
Cylance Unsafe
BitDefender Trojan.GenericKD.31580441
Cybereason malicious.f214df
Arcabit Generic.Application.CoinMiner.1.13CEE283
BitDefenderTheta Gen:NN.ZexaF.34122.@JW@aWOCskej
ESET-NOD32 a variant of Win32/CoinMiner.IF potentially unwanted
Zoner Trojan.Win32.63743
ClamAV Win.Coinminer.Generic-7151253-0
Kaspersky Trojan.Win32.ShadowBrokers.p
NANO-Antivirus Riskware.Win32.BitCoinMiner.hbibwe
Tencent Win32.Trojan.Shadowbrokers.Lgtl
Emsisoft Trojan.GenericKD.31580441 (B)
F-Secure Exploit.EXP/Agent.asbdu
McAfee-GW-Edition BehavesLike.Win32.Trojan.rc
FireEye Generic.mg.3239531f214dfc33
Sophos Generic PUA CD (PUA)
Ikarus PUA.CoinMiner
Cyren W32/Trojan.MKWS-3460
Avira TR/ShadowBrokers.gpoeb
Antiy-AVL Trojan/Win32.ShadowBrokers
Microsoft Program:Win32/Wacapew.C!ml
ZoneAlarm Trojan.Win32.ShadowBrokers.p
VBA32 Trojan.ShadowBrokers
MAX malware (ai score=82)
Ad-Aware Generic.Application.CoinMiner.1.13CEE283
APEX Malicious
Rising PUF.CoinMiner!1.B033 (CLOUD)
Yandex Riskware.Agent!
SentinelOne DFI – Suspicious PE
GData Generic.Application.CoinMiner.1.13CEE283 (2x)
AVG Win32:Miner-DM [Trj]
Avast Win32:Miner-DM [Trj]
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM41.1.8EBD.Malware.Gen

How to remove Win32/CoinMiner.IF potentially unwanted?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

PUA.AgentPMF.S31839339 (file analysis)

The PUA.AgentPMF.S31839339 is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

Barys.431081 (B) removal guide

The Barys.431081 (B) is considered dangerous by lots of security experts. When this infection is…

13 mins ago

MSIL/DllInject.XF potentially unsafe information

The MSIL/DllInject.XF potentially unsafe is considered dangerous by lots of security experts. When this infection…

24 mins ago

Virus.Win32.Luder.B malicious file

The Virus.Win32.Luder.B is considered dangerous by lots of security experts. When this infection is active,…

35 mins ago

About “Heur.Conjar.!c!.3” infection

The Heur.Conjar.!c!.3 is considered dangerous by lots of security experts. When this infection is active,…

40 mins ago

Malware.AI.2068984497 information

The Malware.AI.2068984497 is considered dangerous by lots of security experts. When this infection is active,…

50 mins ago