CUDAMINER.EXE – Trojan CoinMiner

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

CUDAMINER.EXE – Trojan CoinMiner removal

File MD5 Virus Alias
CUDAMINER.EXE d7093d530b0a27a907f2f65535d7f6dc Trojan CoinMiner
CUDAMINER.EXE d7093d530b0a27a907f2f65535d7f6dc Trojan Bitcoin
CUDAMINER.EXE d7093d530b0a27a907f2f65535d7f6dc Trojan Artemis

CUDAMINER.EXE size: 8050688 bytes
CUDAMINER.EXE hash: D7093D530B0A27A907F2F65535D7F6DC

Created files:

C:\Downloads\Software_131231.exe
C:\rwindows\cgminer.exe
C:\rwindows\libcurl-4.dll
C:\rwindows\libeay32.dll
C:\rwindows\libidn-11.dll
C:\rwindows\librtmp.dll
C:\rwindows\libssh2.dll
C:\rwindows\rwindows.exe
C:\rwindows\scrypt130511.cl
C:\rwindows\ssleay32.dll
C:\rwindows\zlib1.dll
C:\temp\after.exe
C:\temp\cudaminer.exe
C:\temp\cudart32_50_35.dll
C:\temp\down.exe
C:\temp\libcurl-4.dll
C:\temp\minerd.exe
C:\temp\pthreadGC2.dll
C:\temp\pthreadVC2.dll
C:\temp\winstart_1312310410.exe
C:\temp\zlib1.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\wstart: C:\temp\winstart_1312310410.exe

Detected by UnHackMe:

CUDAMINER.EXE
Default location: C:\TEMP\CUDAMINER.EXE

Dropper information:
MD5: e57e9fcf8c90e8428a05206ae357b3bb
File size: 10648576 bytes

Leave a Reply