CGMINER.EXE – Trojan CoinMiner

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CGMINER.EXE – Trojan CoinMiner removal

FileMD5Virus Alias
CGMINER.EXE dcb5f700e58341df92c8e52eb798af4c Trojan CoinMiner
CGMINER.EXE dcb5f700e58341df92c8e52eb798af4c Trojan Bitcoin
CGMINER.EXE dcb5f700e58341df92c8e52eb798af4c Trojan SuspiciousFile
CGMINER.EXE dcb5f700e58341df92c8e52eb798af4c Trojan Artemis
CGMINER.EXE dcb5f700e58341df92c8e52eb798af4c Trojan Generic
CGMINER.EXE dcb5f700e58341df92c8e52eb798af4c Trojan Graftor

CGMINER.EXE size: 973326 bytes
CGMINER.EXE hash: DCB5F700E58341DF92C8E52EB798AF4C

Created files:

C:\Downloads\Software_131231.exe
C:\rwindows\cgminer.exe
C:\rwindows\libcurl-4.dll
C:\rwindows\libeay32.dll
C:\rwindows\libidn-11.dll
C:\rwindows\librtmp.dll
C:\rwindows\libssh2.dll
C:\rwindows\rwindows.exe
C:\rwindows\scrypt130511.cl
C:\rwindows\ssleay32.dll
C:\rwindows\zlib1.dll
C:\temp\after.exe
C:\temp\cudaminer.exe
C:\temp\cudart32_50_35.dll
C:\temp\down.exe
C:\temp\libcurl-4.dll
C:\temp\minerd.exe
C:\temp\pthreadGC2.dll
C:\temp\pthreadVC2.dll
C:\temp\winstart_1312310410.exe
C:\temp\zlib1.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\wstart: C:\temp\winstart_1312310410.exe

Detected by UnHackMe:

CGMINER.EXE
Default location: C:\RWINDOWS\CGMINER.EXE

Dropper information:
MD5: e57e9fcf8c90e8428a05206ae357b3bb
File size: 10648576 bytes

Leave a Reply