SHELL.EXE_PART1 – Trojan Btcmine

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SHELL.EXE_PART1 – Trojan Btcmine removal

FileMD5Virus Alias
SHELL.EXE_PART1 b45cfd8f47a17478dea1d23711a54788 Trojan Btcmine

SHELL.EXE_PART1 size: 4000 bytes
SHELL.EXE_PART1 hash: B45CFD8F47A17478DEA1D23711A54788

Created files:

%Program Files%\%appdata%\WindowsHelp\coinutil.dll
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part1
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part10
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part11
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part12
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part13
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part14
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part15
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part2
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part3
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part4
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part5
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part6
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part7
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part8
%Program Files%\%appdata%\WindowsHelp\macro\macromedia.exe_part9
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part1
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part10
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part11
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part12
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part13
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part14
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part15
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part16
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part17
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part18
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part19
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part2
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part20
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part21
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part22
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part23
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part24
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part25
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part26
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part27
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part28
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part3
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part4
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part5
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part6
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part7
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part8
%Program Files%\%appdata%\WindowsHelp\min\miner.dll_part9
%Program Files%\%appdata%\WindowsHelp\openssl.dll
%Program Files%\%appdata%\WindowsHelp\phatk.cl
%Program Files%\%appdata%\WindowsHelp\phatk.ptx
%Program Files%\%appdata%\WindowsHelp\puts.vbs
%Program Files%\%appdata%\WindowsHelp\shel\shell.exe_part1

Detected by UnHackMe:

SHELL.EXE_PART1
Default location: %PROGRAM FILES%\%APPDATA%\WINDOWSHELP\SHEL\SHELL.EXE_PART1

Dropper information:
MD5: 1d0bbbed31391f4c6dfaacb78f914272
File size: 1222314 bytes

Leave a Reply