Severity scale:  

Bitcoin virus. Main types, distribution techniques and removal explained

removal by Jake Doevan - - | Type: Trojans

Bitcoin virus is a type of malware which is capable of abusing victims' resources to mine Bitcoin for criminals

Bitcoin mining malware

Questions about Bitcoin virus

Bitcoin virus is a type of malicious program that seeks to mine Bitcoin cryptocurrency illegally while using victims' CPU power. In some cases, graphics processing unit (GPU) can be utilized as well. The virus typically enters machines via a trojan horse – a backdoor virus that clears the path for coin-mining malware. The extensive usage of computer hardware diminishes overall performance of the device (eventually it can lead to its destruction), as well as increases the amount of electricity consumed, leading to raised electric bills. Users can detect the malware in the Task Manager as a questionable process running in the background, such as XMRig. The Miner.Bitcoinminer or similarly named infection can infiltrate Windows, Mac, and Android devices.

Name Bitcoin virus
Type Trojan
Sub-type Cryptojacker[1]
Detected as Miner.Bitcoinminer; Risckwar.Bitcoinminer, Trojan.BitcoinMiner; PUA.CoinMiner, etc.
Versions CPU Miner,  Vnlgp Miner, etc.
Currencies mined Bitcoin, Monero, Electroneum and others
Distribution Spam emails, fraudulent messages on Skype, EternalBlue exploit, etc.
Symptoms Increased CPU and GPU usage (making the PC hot), software crashes or freezes, slow overall performance of the device 
Susceptible systems  Windows, Mac, Android
 Elimination Download and install an anti-malware tool to remove Bitcoin virus fully

Bitcoin virus is capable of harvesting various crypto, including Monero, Electroneum, Litecoin, Ethereum, although the most prominent one is Bitcoin. It is a virtual currency which was first introduced in 2008. However, the usage of this digital currency increased only in 2011. At the time of the writing, Bitcoins have already reached the circulation rate of more than 17 million as of late May 2018.[2]

There is no surprise that even the most reputable companies accept this currency. However, it is created not through a central monetary agency, but through the computers that perform CPU-intensive crypto calculations. Therefore, cybercriminals are always looking for new ways to take advantage of this feature by creating new versions of Bitcoin miner.

Bitcoin virus is detected under various names, including:

  • Riskware.Miner
  • Trojan.BitMine
  • W32/CoinMiner
  • Trojan.BitMine
  • Trojan.BitCoinMiner
  • PUA.CoinMiner, etc.

There are several variants of BitcoinMiner, as well. The most known of them are called CPU Miner and Vnlgp Miner. Unfortunately, you can hardly notice when your computer gets infected by it. According to experts, this malware attempts to hide by trying to work only when the victim is not using his/her device.

However, you can notice the Bitcoin virus by monitoring your PC’s speed. According to research, the use of the machine’s CPU grows up rapidly when this virus infiltrates it, so don’t ignore such changes. What is more, the Trojan horse might also be capable of opening the back door or download other malicious programs.

Riskware.MinerRiskware.Miner is a form of Bitcoin virus that uses stealth methods to reach the targeted system and perform malicious actions.

If the GPU of your device is used instead of CPU, you will not be able to spot it in the Task Manager. However, you will be able to see stuttering and freezing frames when performing graphics intensive tasks, such as gaming or full HD video processing.

Some users may naturally come to the conclusion that their graphics card is about to break. Nevertheless, if you experience such symptoms, you should download software that can measure temperature and workload on your GPU, and check if Bitcoin Miner infection causes the malfunction.

There are many reasons[3] why your computer might be working slowly – incompatible software or hardware, corrupt system or software files, outdated registry entries and similar issues. However, it is always worth scanning your machine with reputable anti-virus software first. This security software will immediately detect and remove BitcoinMiner from Mac OS X or Windows.

The evolution of Bitcoin miner virus: ransomware variant hit the surface

Bitcoin ransomware is a specific version of Bitcoin malware, which can infiltrate a computer without user’s approval and then encrypt each of his/her files. This threat has been noticed after encrypting the entire network of one medical center in the USA. However, it can also affect regular home users leaving them without the access to their files.

Bitcoin Miner virusBitcoin virus - any type of malware that is used by cybercriminals to illegally mine cryptocurrency on the infected PC.

Once it finishes the encryption of victim’s files, Bitcoin ransomware displays a warning message asking him or her to pay the ransom of 1.5 bitcoin. Please, do NOT pay it as you may end up with nothing! Keep in mind that you are dealing with scammers who can take money from you and leave you without a special code needed to decrypt your locked files.

In this case, you should perform Bitcoin miner virus removal with Reimage Reimage Cleaner Intego and try to encrypt your files with the help of these tools: Photorec and R-studio. Keep in mind that dealing with cybercriminals is never an option!

Bitcoin mining malware has been noticed spreading in Russia

At the end of July 2017, it was reported that cryptocurrency mining malware infected 25% of computer users in Russia. [4] However, some sources state that this cyber infection may have infiltrated 30% of Russian computers.[5]

According to the official data, the majority of affected devices run in Windows OS. Meanwhile, Mac computers and iPhones haven’t suffered a lot from the virus.

Authorities published the information about Bitcoin mining virus[6]. However, security specialists and antivirus vendors claim that the scope of the attack is exaggerated.[7] Experts agree that in the past there were few issues with this malware, but not as vast as it is has been stated recently.

Trojan.BitcoinMinerIt might be difficult to detect the infection; however, high CPU and/or CPU usage is the first indicator which should not be missed.

A representative from Kaspersky Labs, which is one of the leading Russian antivirus vendors, claims that if such a massive attack were held, they would have noticed it. However, since the beginning of the year, only 6% of their customers have suffered from BitcoinMiner.[8]

Ways to get infected with malware

According to security experts, this virus is mostly spread via Skype network, but it has also been noticed on other social networks, so beware about that. Typically, this virus relies on a spam message, which claims something like „this my favorite picture of you” and includes a malicious file. Of course, virus seeks to convince its victims to download the file onto their computers. Certain versions of malware were also seen being spread using the EternalBlue exploit.

If you want to avoid it, stay away from such messages. Once victim downloads the “photo,” he not only lets malicious pieces inside the machine but allows the virus to connect PC to its command-and-control server.

Once inside and active, the virus turns the infected machine to the Bitcoin generator. However, it can also be designed to the virus, which steals banking details, records the keystrokes or downloads more malware on its target PC. 

Bitcoin virus removal guide

If you think that your computer is infected with malware, you should scan it with updated security software, such as Reimage Reimage Cleaner Intego or Malwarebytes. If your device is affected, your chosen security tool will remove Bitcoin virus immediately.

Make sure you check the system immediately after noticing changes in your computer’s speed because it is the only way to get rid of this threat without additional problems. The appearance of other viruses and the loss of your sensitive information can be expected when having Bitcoin malware on a computer.

Bitcoin miner trojanCybercriminals seek to gain monetary benefit by using victims' systems. Do not allow hackers to earn money while compromising your device.

These programs should also help you perform Bitcoin virus removal from the system. However, sometimes viruses that are categorized as ransomware block anti-virus software to prevent their removal. If you are dealing with such problem right now, follow a guide below.

do it now!
Reimage Happiness
Intego Happiness
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage Intego, submit a question to our support team and provide as much details as possible.
Reimage Intego has a free limited scanner. Reimage Intego offers more through scan when you purchase its full version. When free scanner detects issues, you can fix them using free manual repairs or you can decide to purchase the full version in order to fix them automatically.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage, try running SpyHunter 5.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Intego, try running Combo Cleaner.

To remove Bitcoin virus, follow these steps:

Remove Bitcoin using Safe Mode with Networking

If you cannot access security software necessary for Bitcoin ransomware removal, you should follow these steps:

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove Bitcoin

    Log in to your infected account and start the browser. Download Reimage Reimage Cleaner Intego or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete Bitcoin removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove Bitcoin using System Restore

This method helps to disable the virus in order to run its automatic removal.

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of Bitcoin. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage Reimage Cleaner Intego and make sure that Bitcoin removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove Bitcoin from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by security experts.

If your files are encrypted by Bitcoin, you can use several methods to restore them:

Data Recovery Pro helps to recover missing files

If you a ransomware variant of the Bitcoin virus encrypted your files, this tool might help to recover at least some of them.

  • Download Data Recovery Pro;
  • Follow the steps of Data Recovery Setup and install the program on your computer;
  • Launch it and scan your computer for files encrypted by Bitcoin ransomware;
  • Restore them.

Take advantage of Windows Previous Versions feature

This method helps to copy previously saved versions of files. However, System Restore has been enabled before ransomware attack.

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

ShadowExplorer might help to restore files encrypted by Bitcoin ransomware

  • Download Shadow Explorer (;
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Bitcoin and other ransomwares, use a reputable anti-spyware, such as Reimage Reimage Cleaner Intego, SpyHunter 5Combo Cleaner or Malwarebytes

Do not let government spy on you

The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices. Avoid any unwanted government tracking or spying by going totally anonymous on the internet. 

You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using Private Internet Access VPN.

Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.

Backup files for the later use, in case of the malware attack

Computer users can suffer from data losses due to cyber infections or their own faulty doings. Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact – you can set this process to be performed automatically.

When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use Data Recovery Pro for the data restoration process.

About the author
Jake Doevan
Jake Doevan - Computer technology expert

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Jake Doevan
About the company Esolutions

Removal guides in other languages