Malware

About “Win64/CoinMiner.XD” infection

Malware Removal

The Win64/CoinMiner.XD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/CoinMiner.XD virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win64/CoinMiner.XD?


File Info:

name: 5705F26771B0420BD70D.mlw
path: /opt/CAPEv2/storage/binaries/60262d0d3bc436c189d6a9892f435572eae7749df23b22aff9eb459cae6b0469
crc32: 47F6C897
md5: 5705f26771b0420bd70d4e8b45f7bb9f
sha1: 7878e711d98a0c5098ec4feba13fdb34d673ca3e
sha256: 60262d0d3bc436c189d6a9892f435572eae7749df23b22aff9eb459cae6b0469
sha512: 1f06bae93dac32ba306a599d19f6c02cc7d0372ccdabd01fbb3a15bd4c7343981111f36f57447d24d490d9f6e358b7925a90fac18aa432c33fbfb584dba7a8d2
ssdeep: 6144:BXTNMUJz8/ALv6e3tJl/c04lX+ALDok73/oJGy2oNOUXz3nLthn:BPtLi8Je0MBok73KGy2oUUDXvn
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1156423E1414E9D55F81372F6123F1638901DF39C086B9BACBCA0890E87DD669A3643EF
sha3_384: 0ef2314e261013435cbd97f97da6d0f3f8ee9ea88cce9633b599309ce0d410221d47295cb4b948503a8feccb2b5a6183
ep_bytes: 53565755488d352550fbff488dbe00c0
timestamp: 2019-11-26 18:50:52

Version Info:

0: [No Data]

Win64/CoinMiner.XD also known as:

LionicTrojan.Win32.Coinminer.4!c
MicroWorld-eScanTrojan.GenericKD.47581597
FireEyeGeneric.mg.5705f26771b0420b
McAfeeArtemis!5705F26771B0
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win64.6802
K7AntiVirusTrojan ( 0055e2701 )
AlibabaRiskWare:Win64/Miner.8a572418
K7GWTrojan ( 0055e2701 )
Cybereasonmalicious.771b04
SymantecMiner.Bitcoinminer
ESET-NOD32a variant of Win64/CoinMiner.XD
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win64.Miner.gen
BitDefenderTrojan.GenericKD.47581597
AvastWin64:Trojan-gen
TencentMalware.Win32.Gencirc.10cf9534
Ad-AwareTrojan.GenericKD.47581597
EmsisoftTrojan.GenericKD.47581597 (B)
TrendMicroCoinminer_MALXMR.SMSTAK-WIN64
McAfee-GW-EditionBehavesLike.Win64.Dropper.fc
SophosXMR-Stak Miner (PUA)
IkarusPUA.CoinMiner
GDataWin64.Trojan.Agent.R876PB
JiangminRiskTool.Miner.ajz
AviraHEUR/AGEN.1123692
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.2FE8013
GridinsoftRansom.Win64.Gen.sa
ArcabitTrojan.Generic.D2D6099D
ViRobotTrojan.Win32.Z.Agent.312320.IT
CynetMalicious (score: 99)
AhnLab-V3Unwanted/Win32.CoinMiner.C3610076
ALYacTrojan.GenericKD.47581597
MalwarebytesMalware.AI.4201785306
RisingHackTool.CoinMiner!1.BEAB (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Miner
AVGWin64:Trojan-gen
PandaTrj/CI.A

How to remove Win64/CoinMiner.XD?

Win64/CoinMiner.XD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment