Malware

Should I remove “Win64/CoinMiner.HQ”?

Malware Removal

The Win64/CoinMiner.HQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/CoinMiner.HQ virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win64/CoinMiner.HQ?


File Info:

name: CE3EDDE8E05E6E85DF9B.mlw
path: /opt/CAPEv2/storage/binaries/2f8950bee3793790f70b54556d4d1cc4b2391af42a94d4054ce0ed87fd580e39
crc32: 59597C4A
md5: ce3edde8e05e6e85df9b9ed2641cc208
sha1: 7ea48737b0c05a3ce395d06682a3de783b260df9
sha256: 2f8950bee3793790f70b54556d4d1cc4b2391af42a94d4054ce0ed87fd580e39
sha512: 6906004618a5c92812c4f82d66664be88931f4514e56db4b83abb9c113cf0afb4d0c0ccc8062de5811cf8eddfe240963f4820b6f27e47bd5b596b23feb282c63
ssdeep: 49152:nRSZG4H0v8egCCCxYzQ+YEQXTodTM2mHHrvqQB8dxA9BonqrDjqO4tcLe:nqzY8fuk3bQXkdTGrvVKWBoqY7
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T12CB533E86A4F0E27FD09CC345E7CA535A08E44C547FA554094181AAEE86FDAA330E7E7
sha3_384: 260366829c3320f9bc3baa09379514d97850534a1e18552ffdd73b38199cbf8191877d02c1da4f22cf76388203317320
ep_bytes: eb08003e100000000000505152535556
timestamp: 2017-11-29 20:38:01

Version Info:

0: [No Data]

Win64/CoinMiner.HQ also known as:

BkavW32.ArchosauriaAD.Trojan
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.12648928
FireEyeGeneric.mg.ce3edde8e05e6e85
McAfeeGeneric Trojan.en
CylanceUnsafe
ZillyaTrojan.Packed.Win64.170
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051c1841 )
K7GWTrojan ( 0051c1841 )
Cybereasonmalicious.8e05e6
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win64/CoinMiner.HQ
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.12648928
NANO-AntivirusTrojan.Win64.Mlw.evqwyx
AvastWin64:Malware-gen
TencentWin32.Trojan.Generic.Szvi
Ad-AwareTrojan.GenericKD.12648928
SophosMal/Generic-S
ComodoMalware@#2iaw1extk765z
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win64.Spyware.vc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.GenericKD.12648928 (B)
IkarusTrojan.Win64.Enigma
GDataTrojan.GenericKD.12648928
JiangminTrojan.Generic.btpzl
eGambitUnsafe.AI_Score_95%
AviraTR/CoinMiner.ksxfj
Antiy-AVLTrojan/Generic.ASMalwS.22EDDFE
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 99)
VBA32Trojan.Tiggre
ALYacTrojan.GenericKD.12648928
APEXMalicious
YandexTrojan.GenAsa!G4++qMnKcDk
MAXmalware (ai score=99)
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
WebrootW32.Trojan.Gen
AVGWin64:Malware-gen
PandaTrj/RnkBend.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win64/CoinMiner.HQ?

Win64/CoinMiner.HQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment