USFT_EXT.DLL – Trojan CoinMiner

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

USFT_EXT.DLL – Trojan CoinMiner removal

FileMD5Virus Alias
USFT_EXT.DLL 24b959a18440d5faf875f409ebaec4b5 Trojan CoinMiner
USFT_EXT.DLL 24b959a18440d5faf875f409ebaec4b5 Trojan Bitcoin

USFT_EXT.DLL size: 879104 bytes
USFT_EXT.DLL hash: 24B959A18440D5FAF875F409EBAEC4B5

Created files:

%Program Files%\%appdata%\WindowsLogon\coinutil.dll
%Program Files%\%appdata%\WindowsLogon\macro\macromedia.exe_part1
%Program Files%\%appdata%\WindowsLogon\macro\macromedia.exe_part2
%Program Files%\%appdata%\WindowsLogon\macro\macromedia.exe_part3
%Program Files%\%appdata%\WindowsLogon\macro\macromedia.exe_part4
%Program Files%\%appdata%\WindowsLogon\macro\macromedia.exe_part5
%Program Files%\%appdata%\WindowsLogon\macro\macromedia.exe_part6
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part1
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part10
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part11
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part12
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part13
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part14
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part15
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part16
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part17
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part18
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part19
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part2
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part20
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part21
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part22
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part23
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part24
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part25
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part26
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part27
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part28
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part29
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part3
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part30
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part31
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part32
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part33
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part34
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part35
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part4
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part5
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part6
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part7
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part8
%Program Files%\%appdata%\WindowsLogon\min\miner.dll_part9
%Program Files%\%appdata%\WindowsLogon\openssl.dll
%Program Files%\%appdata%\WindowsLogon\phatk.cl
%Program Files%\%appdata%\WindowsLogon\phatk.ptx
%Program Files%\%appdata%\WindowsLogon\puts.vbs
%Program Files%\%appdata%\WindowsLogon\shel\shell.exe_part1
%Program Files%\%appdata%\WindowsLogon\shel\shell.exe_part2
%Program Files%\%appdata%\WindowsLogon\shel\shell.exe_part3
%Program Files%\%appdata%\WindowsLogon\shel\shell.exe_part4
%Program Files%\%appdata%\WindowsLogon\shel\shell.exe_part5
%Program Files%\%appdata%\WindowsLogon\shel\shell.exe_part6
%Program Files%\%appdata%\WindowsLogon\usft_ext.dll
%Program Files%\%appdata%\WindowsLogon\usft_ext.exe.vbs

Detected by UnHackMe:

USFT_EXT.DLL
Default location: %PROGRAM FILES%\%APPDATA%\WINDOWSLOGON\USFT_EXT.DLL

Dropper information:
MD5: 1b95399fd1a67f7a4b85f593b1f3f4e9
File size: 1029916 bytes

Leave a Reply