Malware

Win64/CoinMiner.YP removal

Malware Removal

The Win64/CoinMiner.YP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/CoinMiner.YP virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win64/CoinMiner.YP?


File Info:

crc32: 831F3732
md5: 41a0035a448c864ec74f22a379954358
name: 41A0035A448C864EC74F22A379954358.mlw
sha1: 22edc565da8219633c28698f448ca69e4f8b5492
sha256: 9a21e232b27c16a10fa3585e0475fa36d48f1f1e39e1db1f0a757bf78b9b0e05
sha512: 281f53e2dfed40881a7b64158cf9374a0762f1e6ee61de8f8233259c1bfcc3edc5cd457c95cb78f5258df947516db3ba2fc73ece7f00e59875c61bdb21df2e7b
ssdeep: 12288:pANwRo+mv8QD4+0V16Dx7VqutegGhD8fR3Mcz5adFNjB:pAT8QE+k8xJlsqfedFxB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Earth Side
FileDescription: Game Product 6.5.0 Installation
FileVersion: 6.5.0
Comments:
CompanyName: Earth Side
Translation: 0x0409 0x04e4

Win64/CoinMiner.YP also known as:

K7AntiVirusRiskware ( 0053b5231 )
LionicRiskware.HTML.Miner.1!c
DrWebTrojan.BtcMine.2708
MicroWorld-eScanTrojan.GenericKD.30617114
CAT-QuickHealHTML.Coinminer.38725
ALYacTrojan.GenericKD.30617114
CylanceUnsafe
SangforTrojan.Win32.Miner.DM
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win64/Miners.2d058141
K7GWRiskware ( 0053b5231 )
Cybereasonmalicious.a448c8
SymantecMiner.XMRig!gen1
ESET-NOD32Win64/CoinMiner.YP
APEXMalicious
AvastBV:BitCoinMiner-BS [PUP]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.30617114
NANO-AntivirusTrojan.Win64.BtcMine.ezosht
TencentWin32.Trojan.Generic.Pbyu
SophosGeneric Reputation PUA (PUA)
ComodoMalware@#2q18q66ozo81w
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJJ21
McAfee-GW-EditionRDN/Generic PUP.x
FireEyeTrojan.GenericKD.30617114
EmsisoftTrojan.GenericKD.30617114 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Miner.ctf
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1136970
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/CoinMiner.C!rfn
SUPERAntiSpywareHack.Tool/Gen-BitCoinMiner
GDataTrojan.GenericKD.30617114
AhnLab-V3Trojan/Win32.Miner.R338473
McAfeeRDN/Generic PUP.x
MAXmalware (ai score=98)
VBA32Trojan.Win64.Miner
MalwarebytesMalware.AI.718441685
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DJJ21
YandexRiskware.Agent!d4b6XVt1b9o
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW64/Miner.DP!tr
AVGBV:BitCoinMiner-BS [PUP]
Paloaltogeneric.ml

How to remove Win64/CoinMiner.YP?

Win64/CoinMiner.YP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment