Malware

Win64/CoinMiner.LR potentially unwanted malicious file

Malware Removal

The Win64/CoinMiner.LR potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/CoinMiner.LR potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win64/CoinMiner.LR potentially unwanted?


File Info:

name: 01E212BED85589B269AC.mlw
path: /opt/CAPEv2/storage/binaries/d0f8dfac41ef08c43204b3d9da5a5ee97b635e1fea19435bd51c3f7c0267129d
crc32: 34167E68
md5: 01e212bed85589b269ace25ad00c2403
sha1: 99941afab8d378971b5817ee2bb34779fd8bd4ba
sha256: d0f8dfac41ef08c43204b3d9da5a5ee97b635e1fea19435bd51c3f7c0267129d
sha512: e017b95d3f6ddb6c431b5631301ddcab5ba2c5acaa6087c69f9444aba81621fea241441749ce1bfcdbf8aaa49d319363dcf9dbe2c03b3d480506b449e8323d4c
ssdeep: 49152:+ztDe3Mpztphq/dvKiv8y7xeRQwVCkKiuINmYL5qPGl:vcXCvKi0KiuIj1l
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1DCB59E56E3A401F4D9B7C13CC9529617EBF2B8191370A7DB0AA446BA1F23BE51E3E710
sha3_384: 1256b9956a62a0111448459bfa5517f190d6ec58057e06e453c36cb4ff041536dae02200db9040cd0c3893c27f3be7c9
ep_bytes: 4883ec28e8530800004883c428e976fe
timestamp: 2019-05-26 03:48:16

Version Info:

0: [No Data]

Win64/CoinMiner.LR potentially unwanted also known as:

AlibabaRiskWare:Win64/Miners.b56a1d8a
SymantecW32.Mandaph
ESET-NOD32a variant of Win64/CoinMiner.LR potentially unwanted
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.gen
AvastWin64:Malware-gen
ComodoApplicUnwnt@#33ctt74fw3892
SophosGeneric PUA JJ (PUA)
Antiy-AVLTrojan/Generic.ASMalwS.2BC5908
MicrosoftPUA:Win32/Presenoker
FortinetRiskware/CoinMiner
AVGWin64:Malware-gen
Cybereasonmalicious.ab8d37

How to remove Win64/CoinMiner.LR potentially unwanted?

Win64/CoinMiner.LR potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment