Windows Defender PUA:Win32/CoinMiner Active? False Positive Or Malicious Version?

Hi,

I've scanned my PC with Windows Defender today and it detected a PUA:Win32/CoinMiner (screenshot below). It's an old Electrum 3.3.8 Portable executable (bitcoin wallet) which I downloaded last year. I also uploaded it to Virustotal where some other engines also detected the file as a PUP, results are here.

So I checked my browser history to see if I downloaded it from the offical site which I did and I also checked the signature of the executable with GPG and it was good. I also noticed that when downloading the exe again from the official site it also gets detected.

Of course that would normally be it and I wouldn't worry about it but I thought it was kind a strange is that Windows Defender says it's an active threat. Does that mean it was running or doing anything or simply that it hasn't been dealt with? It would worry me a little if it was running or doing anything because I only downloaded it many months ago but never actually used it because I decided to use something different.

I also wondered why it wasn't detected during any other scan before over all these months where it was sitting on my desktop but I guess that's probably because of a recent definition update.

Sorry for my amateur questions, haven't really had any potential threats on my system before.

Microsoft has only just added active PUP/PUA scanning to Defender, previously it could be activated via group policy I believe.

Try running these programs:
MBAM free: https://www.malwarebytes.com/mwb-download/
Adwcleaner: https://www.malwarebytes.com/adwcleaner/

If you’re still worrried afterwards then register with one of these sites to request help with cleaning up the PUA or confirming it isn’t a concern.
https://forums.malwarebytes.com/forum/7-windows...
Bleeping computer malware/virus removal forum:
https://www.bleepingcomputer.com/forums/forum22...

Disclaimer - This post contains reference to non-Microsoft websites and there may be ads on the page for products & services including products frequently classified as a PUP (Potentially Unwanted Product). Please thoroughly research any product / service advertised on the page before you decide to use them. Your discretion is very much advised.
Virginia - Time Lady.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I just came up with the same thing and found this.  I would not want to mess with this error unnecessarily.  I was using Electrum 3.3.8 portable, I had the seed so I just downloaded the new version and used the seed to rebuild the data.  Then I archived the old version.

1 person found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

 
 

Question Info


Last updated April 2, 2024 Views 1,665 Applies to: