USFT_EXT.DLL – Trojan CoinMiner

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

USFT_EXT.DLL – Trojan CoinMiner removal

FileMD5Virus Alias
USFT_EXT.DLL 24b959a18440d5faf875f409ebaec4b5 Trojan CoinMiner
USFT_EXT.DLL 24b959a18440d5faf875f409ebaec4b5 Trojan Bitcoin

USFT_EXT.DLL size: 879104 bytes
USFT_EXT.DLL hash: 24B959A18440D5FAF875F409EBAEC4B5

Created files:

%Program Files%\%appdata%\WindowsLogonSS\coinutil.dll
%Program Files%\%appdata%\WindowsLogonSS\macro\macromedia.exe_part1
%Program Files%\%appdata%\WindowsLogonSS\macro\macromedia.exe_part2
%Program Files%\%appdata%\WindowsLogonSS\macro\macromedia.exe_part3
%Program Files%\%appdata%\WindowsLogonSS\macro\macromedia.exe_part4
%Program Files%\%appdata%\WindowsLogonSS\macro\macromedia.exe_part5
%Program Files%\%appdata%\WindowsLogonSS\macro\macromedia.exe_part6
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part1
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part10
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part11
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part12
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part13
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part14
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part15
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part16
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part17
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part18
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part19
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part2
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part20
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part21
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part22
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part23
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part24
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part25
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part26
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part27
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part28
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part29
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part3
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part30
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part31
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part32
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part33
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part34
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part35
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part4
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part5
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part6
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part7
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part8
%Program Files%\%appdata%\WindowsLogonSS\min\miner.dll_part9
%Program Files%\%appdata%\WindowsLogonSS\openssl.dll
%Program Files%\%appdata%\WindowsLogonSS\phatk.cl
%Program Files%\%appdata%\WindowsLogonSS\phatk.ptx
%Program Files%\%appdata%\WindowsLogonSS\puts.vbs
%Program Files%\%appdata%\WindowsLogonSS\shel\shell.exe_part1
%Program Files%\%appdata%\WindowsLogonSS\shel\shell.exe_part2
%Program Files%\%appdata%\WindowsLogonSS\shel\shell.exe_part3
%Program Files%\%appdata%\WindowsLogonSS\shel\shell.exe_part4
%Program Files%\%appdata%\WindowsLogonSS\shel\shell.exe_part5
%Program Files%\%appdata%\WindowsLogonSS\shel\shell.exe_part6
%Program Files%\%appdata%\WindowsLogonSS\usft_ext.dll
%Program Files%\%appdata%\WindowsLogonSS\usft_ext.exe.vbs

Detected by UnHackMe:

USFT_EXT.DLL
Default location: %PROGRAM FILES%\%APPDATA%\WINDOWSLOGONSS\USFT_EXT.DLL

Dropper information:
MD5: 185180478b3d3d58c696b172fee24c57
File size: 1049014 bytes

Leave a Reply