Malware

Should I remove “Win64/CoinMiner.KT potentially unwanted”?

Malware Removal

The Win64/CoinMiner.KT potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/CoinMiner.KT potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win64/CoinMiner.KT potentially unwanted?


File Info:

name: B0D47F4183FB20FA84D0.mlw
path: /opt/CAPEv2/storage/binaries/bd115a2cfc10d25dc41553e19230c54f8eb378c33b5de1c60a9f7f8a40bdfea4
crc32: A08A77E1
md5: b0d47f4183fb20fa84d0f82b625991bd
sha1: 9866fae3d668e96ca613b4a8f70272d5d0b845f4
sha256: bd115a2cfc10d25dc41553e19230c54f8eb378c33b5de1c60a9f7f8a40bdfea4
sha512: 640a56333e6de5414ee91663ec497019ba9786a54159821a57741195e30e902c24f5ecb603f5f4d3153c42e040a5a4b2929c6757f87870af82e88f245cc03694
ssdeep: 49152:O2uw+c6UJAoDWeOPr4whuJQne2N0gjiXMVA8ISGX+9z9SJ4cL1bvg3Jp5jb3yPph:wt7WF00gjoKz99+S3JqxAu3cZhY
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T13C26AE057A56E0E6C5BEE07985B68A47E2B1B495073087FB46E0225A1F33BD1DE3F381
sha3_384: 9db1bd2bfe40517da67e3072c291e4f43b67f2d9d037648bb5a4bb2a7f9d72cd31e59fa5d01b727346873ad983ad43a7
ep_bytes: 4883ec28e88f0700004883c428e976fe
timestamp: 2018-01-04 11:54:56

Version Info:

0: [No Data]

Win64/CoinMiner.KT potentially unwanted also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.CoinMiner.34
FireEyeGeneric.mg.b0d47f4183fb20fa
McAfeeArtemis!B0D47F4183FB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005273f11 )
K7GWTrojan ( 005273f11 )
Cybereasonmalicious.183fb2
SymantecTrojan.Gen
ESET-NOD32a variant of Win64/CoinMiner.KT potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CJM21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Application.CoinMiner.34
NANO-AntivirusTrojan.Win64.Wdfload.exqojl
AvastWin64:Malware-gen
Ad-AwareGen:Variant.Application.CoinMiner.34
ZillyaTrojan.Generic.Win32.1384531
McAfee-GW-EditionBehavesLike.Win64.Injector.rc
EmsisoftGen:Variant.Application.CoinMiner.34 (B)
JiangminTrojan.Generic.ckvih
AviraTR/BitCoinMiner.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.23FAFFD
KingsoftWin32.Troj.Undef.(kcloud)
GDataGen:Variant.Application.CoinMiner.34
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win64.CoinMiner.R266451
Acronissuspicious
VBA32Trojan.Win64.Wdfload
ALYacGen:Variant.Application.CoinMiner.34
MalwarebytesMalware.AI.1616245985
TencentWin64.Trojan.Wdfload.Pfiy
YandexTrojan.GenAsa!LK+g0QLA0+0
IkarusTrojan.Win64.Wdfload
FortinetPossibleThreat
WebrootW32.Trojan.Gen
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Win64/CoinMiner.KT potentially unwanted?

Win64/CoinMiner.KT potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment