CSRSS.EXE – Trojan CoinMiner

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CSRSS.EXE – Trojan CoinMiner removal

FileMD5Virus Alias
CSRSS.EXE 21f2cd5ce21e517de5d4fe3e2882f772 Trojan CoinMiner
CSRSS.EXE 21f2cd5ce21e517de5d4fe3e2882f772 Trojan Bitcoin
CSRSS.EXE 21f2cd5ce21e517de5d4fe3e2882f772 Trojan Btcmine
CSRSS.EXE 21f2cd5ce21e517de5d4fe3e2882f772 Trojan Generic
CSRSS.EXE 21f2cd5ce21e517de5d4fe3e2882f772 Trojan FakeAV

CSRSS.EXE size: 168448 bytes
CSRSS.EXE hash: 21F2CD5CE21E517DE5D4FE3E2882F772

Created files:

%Program Files%\%appdata%\Java\Update\Download\Cache\csrss.exe
%Program Files%\%appdata%\Java\Update\Download\Cache\diablo121016.cl
%Program Files%\%appdata%\Java\Update\Download\Cache\diakgcn121016.cl
%Program Files%\%appdata%\Java\Update\Download\Cache\jsheded.exe
%Program Files%\%appdata%\Java\Update\Download\Cache\libcurl-4.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\libeay32.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\libidn-11.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\libpdcurses.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\libusb-1.0.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\OpenCL.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\phatk121016.cl
%Program Files%\%appdata%\Java\Update\Download\Cache\poclbm121016.cl
%Program Files%\%appdata%\Java\Update\Download\Cache\pthreadGC2.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\ssleay32.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\zlib1.dll

Detected by UnHackMe:

CSRSS.EXE
Default location: %PROGRAM FILES%\%APPDATA%\JAVA\UPDATE\DOWNLOAD\CACHE\CSRSS.EXE

Dropper information:
MD5: cbb74dbefa75bef8460b54ffb99000e5
File size: 1392430 bytes

Leave a Reply