CSRSS.EXE – Trojan CoinMiner

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CSRSS.EXE – Trojan CoinMiner removal

File MD5 Virus Alias
CSRSS.EXE 207e8913fb9874d344c4b7841ea2a013 Trojan CoinMiner
CSRSS.EXE 207e8913fb9874d344c4b7841ea2a013 Worm AMN

CSRSS.EXE size: 409088 bytes
CSRSS.EXE hash: 207E8913FB9874D344C4B7841EA2A013

Created files:

%Program Files%\%appdata%\Java\Update\Download\Cache\csrss.exe
%Program Files%\%appdata%\Java\Update\Download\Cache\diablo121016.cl
%Program Files%\%appdata%\Java\Update\Download\Cache\diakgcn121016.cl
%Program Files%\%appdata%\Java\Update\Download\Cache\jsheded.exe
%Program Files%\%appdata%\Java\Update\Download\Cache\libcurl-4.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\libeay32.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\libidn-11.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\libpdcurses.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\libusb-1.0.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\OpenCL.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\phatk121016.cl
%Program Files%\%appdata%\Java\Update\Download\Cache\poclbm121016.cl
%Program Files%\%appdata%\Java\Update\Download\Cache\pthreadGC2.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\ssleay32.dll
%Program Files%\%appdata%\Java\Update\Download\Cache\zlib1.dll

Detected by UnHackMe:

CSRSS.EXE
Default location: %PROGRAM FILES%\%APPDATA%\JAVA\UPDATE\DOWNLOAD\CACHE\CSRSS.EXE

Dropper information:
MD5: 6d0c0c23c4ee24467e373bbcdb693892
File size: 1321138 bytes

Leave a Reply