Malware

About “Win32/CoinMiner.JU potentially unwanted” infection

Malware Removal

The Win32/CoinMiner.JU potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/CoinMiner.JU potentially unwanted virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
xmr.pool.minergate.com

How to determine Win32/CoinMiner.JU potentially unwanted?


File Info:

crc32: 0824BD1C
md5: b01d08a527758523ecfb6407b3867b61
name: B01D08A527758523ECFB6407B3867B61.mlw
sha1: 98be991e1ecb72c2421783db588d92271f9bea6a
sha256: 2669fa987515dbecb58f2812a1221786f4d4eedbc014950b839e2359f8e480e0
sha512: 2d34e45648bd71bd1421b8b5e430ffa2f89d6c8846cb95960a6a6917d1ef9c99858d2952bcbd5e5989e141b2199fcd77c44d13e7b8b11bb98e6e064df9a25e64
ssdeep: 24576:6moO8itZ6ZidIVUp29boahPvMyDaN9cYZCC0xaWDO7U:xWZgKUp29boaxvMyDo3ZCdYWi7U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/CoinMiner.JU potentially unwanted also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 0057b6751 )
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.DownLoader26.54473
ClamAVWin.Dropper.DarkKomet-9370806-0
McAfeePUP-HBU
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 0057b6751 )
Cybereasonmalicious.527758
CyrenW32/S-8a06ef73!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.JU potentially unwanted
APEXMalicious
AvastSFX:Agent-E [Trj]
KasperskyTrojan.Win32.Miner.ueii
BitDefenderTrojan.GenericKD.40299064
NANO-AntivirusTrojan.Win32.Miner.ferdnb
MicroWorld-eScanTrojan.GenericKD.40299064
TencentWin32.Trojan.Miner.Pavd
Ad-AwareTrojan.GenericKD.40299064
SophosTroj/Miner-QC
ComodoMalware@#2nm45orpdtjdp
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.b01d08a527758523
EmsisoftTrojan.GenericKD.40299064 (B)
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Ditertag.A
GDataTrojan.GenericKD.40299064
VBA32Trojan.Miner
MAXmalware (ai score=85)
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H06F621
IkarusPUA.CoinMiner
FortinetBAT/CoinMiner.CBBD!tr
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml

How to remove Win32/CoinMiner.JU potentially unwanted?

Win32/CoinMiner.JU potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment