Threat Database Trojans Trojan.Coinminer

Trojan.Coinminer

By CagedTech in Trojans

Threat Scorecard

Ranking: 893
Threat Level: 80 % (High)
Infected Computers: 123,520
First Seen: February 16, 2018
Last Seen: September 21, 2023
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Coinminer

File System Details

Trojan.Coinminer may create the following file(s):
# File Name MD5 Detections
1. is-TV19V.tmp 1bf48abe5f3f1f61a4bf7ebd5adaa75b 1,793
2. conime.exe c50bb65871b46075aeb0d035671ffbbf 880
3. juched.exe 443cfef1b32029f6461c6f1078930714 365
4. kbdusa.exe 71bde539d6d95347337ccd34ac60f335 172
5. dplayx.exe c4edddcafdded4042549ebeedc87281d 63
6. rpcnsh.exe 54eb5b4813124a80eadc49c0e1f6e874 62
7. msvc.exe 0447d246d87a2498f24d9b1910099aa8 61
8. conhost.exe 7b994eaf4457a89935deb269d5c25a94 45
9. winlogui.exe 034faf2273577d9f9bbbbf5fe568fd51 16
10. FIHF.exe f9e52bad1d1c89ceb5fcf89a9b6dc38e 10
11. ctfmon.exe 6e9dfc6d15a5c3bee4a08db1b441aba7 6
12. appextb.exe 010f027e58ba31a56035a4efd1338839 6
13. d3dcompiler_41.exe 4651788d85634163b50c28e65ed7a3cd 6
14. igfxpers.exe ea5e45ae2b6ca1d396105cec2649c1b3 5

Registry Details

Trojan.Coinminer may create the following registry entry or registry entries:
File name without path
jce_cn_cpu_miner64.exe
Windows Vision Driver Foundation Update Check (WDF).exe
Regexp file mask
%ALLUSERSPROFILE%\AdobeAAM\NetFramework.exe
%ALLUSERSPROFILE%\dllhosts.exe
%ALLUSERSPROFILE%\Microsoft\Windows\Caches\svchost.exe
%ALLUSERSPROFILE%\opencl.exe
%ALLUSERSPROFILE%\performance tool\conhost.exe
%ALLUSERSPROFILE%\RealtekHD\taskhostw.exe
%APPDATA%\dssec\dssec.exe
%APPDATA%\GoogleChrome[RANDOM CHARACTERS].exe
%APPDATA%\intpooo.exe
%APPDATA%\Macromedia\svchost.exe
%APPDATA%\Microsoft Visual Studio C++\msvc.exe
%APPDATA%\System\svgost.exe
%COMMONPROGRAMFILES%\conime.exe
%COMMONPROGRAMFILES(x86)%\conime.exe
%HOMEDRIVE%\cex6.exe
%HOMEDRIVE%\Performs\taskhost.exe
%programfiles%\fifa 20\fifa20.exe
%PROGRAMFILES%\svchost.exe
%programfiles(x86)%\fifa 20\fifa20.exe
%PROGRAMFILES(x86)%\svchost.exe
%USERPROFILE%\Documents\mlog.exe
%WINDIR%\debug\winlogonr.exe
%WINDIR%\fonts\sqlservr.exe
%WINDIR%\System32\winlogui.exe
%WINDIR%\TEMP\mess1.exe

Directories

Trojan.Coinminer may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\adwxcssgvy
%ALLUSERSPROFILE%\Application Data\clr_optimization_v4.0.30328_64
%ALLUSERSPROFILE%\Application Data\clr_optimization_v4.0.33018_64
%ALLUSERSPROFILE%\Logss
%ALLUSERSPROFILE%\SteganosNotifierServiceWenter
%ALLUSERSPROFILE%\adwxcssgvy
%ALLUSERSPROFILE%\clr_optimization_v4.0.30328_64
%ALLUSERSPROFILE%\clr_optimization_v4.0.33018_64
%APPDATA%\ExplorerInternets
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\7ZipArchiver
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\IntelCorporalion
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\Macro
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\Microsoft
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\Orion
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\SmartServiceScreenWenter
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\WmiPrvSE
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\adobe
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\adobee
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\gtopapkamaixz
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\kingusuanlaola
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\kingusunlaola
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\kingusunlola
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\minecrofnm
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\minepapkamxsz
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\netrosh
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\randpapkamainof
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\randwpapkamain
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\rneadwpapkamain
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\rneadwpapkaxzai
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\rqnadpapkamain
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\rqnadpapkamaixz
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\stegnmxsdbe
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\steuagnagtmsndbe
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\steuagntmsndbe
%APPDATA%\Microsoft\SystemCertificates\My\CTLs\stolpapkaxzmasi
%APPDATA%\honey miner
%HOMEDRIVE%\$RECYCLE.BIN.EXE
%HOMEDRIVE%\$RECYCLE.EXE.JPG
%HOMEDRIVE%\kernels
%LOCALAPPDATA%\AwesomeMiner
%LOCALAPPDATA%\svc10.17134
%PROGRAMFILES%\awesome miner
%PROGRAMFILES(x86)%\awesome miner
%TEMP%\tratata
%appdata%\Idle

Related Posts

Trending

Most Viewed

Loading...