In this message, I am going to clarify how the CoinHive trojan injected right into your computer, and also how to eliminate CoinHive trojan virus.
What is CoinHive trojan?
Name | CoinHive |
Infection Type | Trojan |
Symptoms |
|
Similar behavior | Bitsaload, SpyNoon, MassLogger, Eqtonex, Pandopera, Packect |
Fix Tool | See If Your System Has Been Affected by CoinHive trojan |
Trojan viruses are one of the leading malware kinds by its injection frequency for quite a very long time. And now, during the pandemic, when malware became tremendously active, trojan viruses raised their activity, too. You can see a number of messages on different resources, where users are complaining about the CoinHive trojan virus in their computers, and asking for assistance with CoinHive trojan virus elimination.
Trojan CoinHive is a type of virus that injects right into your computer, and then executes a wide range of destructive functions. These functions depend on a kind of CoinHive trojan: it can serve as a downloader for many other malware or as a launcher for another malicious program which is downloaded together with the CoinHive trojan virus. During the last 2 years, trojans are additionally distributed using e-mail add-ons, and most of cases used for phishing or ransomware injection.
CoinHive2 also known as
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Johnnie.268188 |
FireEye | Gen:Variant.Johnnie.268188 |
CAT-QuickHeal | Trojan.Tasker |
ALYac | Gen:Variant.Johnnie.268188 |
Cylance | Unsafe |
VIPRE | Win32.Malware!Drop |
AegisLab | Trojan.Win32.Tasker.4!c |
K7AntiVirus | Trojan ( 0052ad991 ) |
BitDefender | Gen:Variant.Johnnie.268188 |
K7GW | Trojan ( 0052ad991 ) |
CrowdStrike | win/malicious_confidence_60% (W) |
Cyren | W32/CoinMiner.AU.gen!Eldorado |
Symantec | Trojan.Gen.MBT |
APEX | Malicious |
Avast | Win32:Trojan-gen |
ClamAV | Win.Virus.Sality-6824452-0 |
Kaspersky | Trojan.Win32.Tasker.it |
Alibaba | Trojan:Win32/Tasker.6ef4d277 |
NANO-Antivirus | Trojan.Win32.Starter.hyvdzv |
Rising | Trojan.CoinMiner/BAT!1.BA78 (CLASSIC) |
Ad-Aware | Gen:Variant.Johnnie.268188 |
Emsisoft | Gen:Variant.Johnnie.268188 (B) |
Comodo | Malware@#25sza85qzbpy0 |
F-Secure | Heuristic.HEUR/AGEN.1103339 |
DrWeb | Trojan.Siggen10.15756 |
TrendMicro | TROJ_GEN.R002C0DHG20 |
McAfee-GW-Edition | RDN/Generic.dx |
Sophos | Mal/Generic-S |
Ikarus | Trojan.Win32.Agent |
Webroot | W32.Malware.Gen |
Avira | TR/Agent.wfivx |
Kingsoft | Win32.Troj.Generic_a.a.(kcloud) |
Microsoft | Trojan:JS/CoinHive |
Gridinsoft | Trojan.Win32.Agent.vb |
Arcabit | Trojan.Johnnie.D4179C |
ZoneAlarm | HEUR:Trojan-Dropper.Win32.Miner.gen |
GData | Gen:Variant.Johnnie.268188 |
Cynet | Malicious (score: 85) |
AhnLab-V3 | Malware/Win32.Generic.C4191145 |
McAfee | RDN/Generic.dx |
Malwarebytes | Trojan.BitCoinMiner |
Panda | Trj/CI.A |
ESET-NOD32 | multiple detections |
TrendMicro-HouseCall | TROJ_GEN.R002C0DHG20 |
Tencent | Win32.Trojan.Tasker.Szcb |
Yandex | Trojan.GenAsa!RJYiYgJNhqk |
MAX | malware (ai score=100) |
MaxSecure | Trojan.Malware.73632073.susgen |
Fortinet | W32/Generic.AC.418957 |
BitDefenderTheta | AI:Packer.E42E5E991F |
AVG | Win32:Trojan-gen |
Cybereason | malicious.1b2979 |
Paloalto | generic.ml |
Qihoo-360 | Win32/Trojan.5d8 |
Domains that associated with CoinHive:
0 | z.whorecord.xyz |
1 | a.tomx.xyz |
2 | 2no.co |
3 | iplogger.org |
4 | ocsp.comodoca.com |
5 | ocsp.usertrust.com |
6 | w.c1ts.ru |
7 | ocsp.sectigo.com |
What are the symptoms of CoinHive trojan?
- At least one process apparently crashed during execution;
- Attempts to connect to a dead IP:Port (3 unique times);
- Creates RWX memory;
- Detected script timer window indicative of sleep style evasion;
- A process attempted to delay the analysis task.;
- Reads data out of its own binary image;
- A process created a hidden window;
- Drops a binary and executes it;
- HTTP traffic contains suspicious features which may be indicative of malware related traffic;
- Performs some HTTP requests;
- Unconventionial language used in binary resources: Russian;
- A scripting utility was executed;
- Uses Windows utilities for basic functionality;
- Network activity contains more than one unique useragent.;
- Installs itself for autorun at Windows startup;
- Creates a hidden or system file;
- Checks the system manufacturer, likely for anti-virtualization;
- Attempts to modify proxy settings;
- Uses suspicious command line tools or Windows utilities;
The frequent symptom of the CoinHive trojan virus is a steady entrance of various malware – adware, browser hijackers, et cetera. As a result of the activity of these harmful programs, your system becomes very sluggish: malware utilizes substantial amounts of RAM and CPU capacities.
Another detectable impact of the CoinHive trojan virus visibility is unknown operations showed in task manager. Often, these processes may attempt to simulate system processes, however, you can understand that they are not legit by checking out the origin of these processes. Pseudo system applications and CoinHive trojan’s processes are always specified as a user’s tasks, not as a system’s.
How to remove CoinHive trojan virus?
- Download and install Loaris Trojan Remover.
- Open Loaris and perform a “Standard scan“.
- “Move to quarantine” all items.
- Open “Tools” tab – Press “Reset Browser Settings“.
- Approve the reset pressing “Yes” button in the appeared window.
- Restart your computer.
To clean up CoinHive trojan and also ensure that all extra malware, downloaded with the help of this trojan, will be eliminated, too, I’d suggest you to use Loaris Trojan Remover.
CoinHive removal guide
To detect and delete all malicious items on your personal computer using Loaris Trojan Remover, it’s better to make use of Standard or Full scan. Removable scan, as well as Custom, will scan only specified locations, so such scans are not able to provide the full information.
You can see the detects during the scan process lasts. Nonetheless, to perform any actions against detected malicious items, you need to wait until the scan is finished, or to interrupt the scanning process.
To designate the appropriate action for each detected malicious programs, click the arrow in front of the name of detected malicious programs. By default, all malicious programs will be sent to quarantine.
How to remove CoinHive Trojan?
Name: CoinHive
Description: Trojan CoinHive is a kind of virus that infiltrates into your computer, and after that performs different destructive functions. These features depend upon a type of CoinHive trojan: it can act as a downloader for many other malware or as a launcher for another destructive program which is downloaded in addition to the CoinHive trojan. During the last two years, trojans are also dispersed via e-mail attachments, and most of situations utilized for phishing or ransomware infiltration.
Operating System: Windows
Application Category: Trojan