Home Malware Programs Trojans Program:Win32/CoinMiner

Program:Win32/CoinMiner

Posted: September 13, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 3,726
First Seen: September 13, 2011
Last Seen: October 14, 2022
OS(es) Affected: Windows

Win32.CoinMiner is a mining client for Windows that creates coins for the BitCoin decentralized economy by conducting some highly complex computations. Win32.CoinMiner may be distributed by other malware threats and run without a PC user's knowledge. Win32.CoinMiner uses system CPU intensively to create coins. Win32.CoinMiner isn't a malware infection, but the fact that it operates in the background makes it popular among cybercriminals to drop it to affected PC users' computers without their knowledge. Then Win32.CoinMiner uses the targeted machine's CPU and creates coins for attackers. If your security application detected Win32.CoinMiner on your computer and you haven't installed it, this might indicate that your PC is corrupted by Trojans or PC threats. Therefore, it is recommended to scan your computer system. If you installed Win32.CoinMiner onto your computer, your anti-virus warning is fake-positive, so you can reject it.

Aliases

Hider.RFC [AVG]Unwanted/Win32.BitCoinMiner [AhnLab-V3]BAT_MINER.JNP [TrendMicro]TR/Rogue.kdv.659220 [AntiVir]Tool.HideApp.44 [DrWeb]Trojan.BAT.Miner.aa [Kaspersky]Artemis!61AB4E0819F5 [McAfee]Artemis!C8A7FD79AEBE [McAfee]Win32.SPRTool.CoinMi [eSafe]Generic PUP.z!hq [McAfee]DR/Aragon.SS [AntiVir]ApplicUnsaf.Win32.RiskTool.HideExec.R [Comodo]Generic.tra!g [McAfee]Generic29.FGV [AVG]Virus.Win32.Crypted [Ikarus]
More aliases (493)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Virtualization\Virtualization.exe File name: Virtualization.exe
Size: 1.13 MB (1132544 bytes)
MD5: edda4a6147c12d1f8a8d52b6acb750d2
Detection count: 1,810
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Virtualization\Virtualization.exe
Group: Malware file
Last Updated: September 25, 2023
%LOCALAPPDATA%\256181942012min.exe File name: 256181942012min.exe
Size: 294.4 KB (294400 bytes)
MD5: ba61c9b0b2b0c33abead5add9e5d49d7
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: February 11, 2013
%APPDATA%\bbjjoditgcybpryccus.exe File name: bbjjoditgcybpryccus.exe
Size: 1.04 MB (1047552 bytes)
MD5: d911d82dc184bbfc952b77cb4cb1b743
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: August 21, 2012
%APPDATA%\DgvQZLPLMy.exe File name: DgvQZLPLMy.exe
Size: 1.04 MB (1047552 bytes)
MD5: fa4c8ba130dc6eba7bcbc424ba4d86f7
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: October 29, 2012
%TEMP%\RarSFX2\msn.exe File name: msn.exe
Size: 946.17 KB (946176 bytes)
MD5: 0600b00040151c6ebbdd404cff7548a5
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX2
Group: Malware file
Last Updated: November 14, 2012
%APPDATA%\2155.exe File name: 2155.exe
Size: 335.36 KB (335360 bytes)
MD5: f3230b07913b74fe7c0d752684d64460
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 14, 2013
%APPDATA%\noultp.exe File name: noultp.exe
Size: 965.55 KB (965552 bytes)
MD5: c3cd2aef8d1ed3d182853b14ed94ee6a
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: September 10, 2012
%APPDATA%\2194.exe File name: 2194.exe
Size: 459.34 KB (459342 bytes)
MD5: 826de0356595eb31e4da3df9f248ea97
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 2, 2013
%TEMP%\Updates\msusm.exe File name: msusm.exe
Size: 738.71 KB (738712 bytes)
MD5: 20d5c788a075113145261ee5dfab0fa0
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Updates
Group: Malware file
Last Updated: August 2, 2012
%APPDATA%\1GrMn4QNPvDJrPvVHu6MmyXJHZU8pr8Q41.exe File name: 1GrMn4QNPvDJrPvVHu6MmyXJHZU8pr8Q41.exe
Size: 1.52 MB (1521275 bytes)
MD5: 1ae0e185cbdf7fb9288fd31ff21dd0cc
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: November 16, 2012
%USERPROFILE%\Start Menu\Programs\Startup\WINLOGONs.exe File name: WINLOGONs.exe
Size: 278.52 KB (278528 bytes)
MD5: 8f0c96820ddc6fa104acb3888ab64670
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: October 22, 2012
%APPDATA%\oa.exe File name: oa.exe
Size: 604.91 KB (604916 bytes)
MD5: b4c750ca23bc480f545414737a0332e0
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: July 20, 2012
C:\Users\<username>\AppData\Roaming\gmin.exe File name: gmin.exe
Size: 289.79 KB (289792 bytes)
MD5: 01aa8f9282d12692a24ffd7d0dbb82cd
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\gmin.exe
Group: Malware file
Last Updated: December 15, 2020
%APPDATA%\koayedenynfgiojdgxy.exe File name: koayedenynfgiojdgxy.exe
Size: 1.04 MB (1047552 bytes)
MD5: c8a7fd79aebecd8fa38bb2992e05ea43
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 13, 2013
%APPDATA%\SystemProcess\SystemProcess.exe File name: SystemProcess.exe
Size: 1.04 MB (1047040 bytes)
MD5: d0a255b0589afa290b0f87a55124498e
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\SystemProcess
Group: Malware file
Last Updated: September 17, 2012
%APPDATA%\cmin.exe File name: cmin.exe
Size: 952.83 KB (952832 bytes)
MD5: 2b632fc62ee59e436eb468d53c00bedd
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 13, 2020
%APPDATA%\folder25\svchost.exe File name: svchost.exe
Size: 158.2 KB (158208 bytes)
MD5: 9a143c0abf37e2b36a9bfb437ad13384
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\folder25
Group: Malware file
Last Updated: October 18, 2012
%APPDATA%\qofyvhmxyppjengxufp.exe File name: qofyvhmxyppjengxufp.exe
Size: 1.04 MB (1047552 bytes)
MD5: 6c9c003493f680a481111c6af775e7cf
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: October 22, 2012
%APPDATA%\Coin.exe File name: Coin.exe
Size: 605.13 KB (605136 bytes)
MD5: bb2bcbee338b1857ae192222393ac716
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: July 20, 2012
%APPDATA%\sdwalioxfifnprxkvxq.exe File name: sdwalioxfifnprxkvxq.exe
Size: 1.04 MB (1047552 bytes)
MD5: affeda4ec44daa759c75069a2234545a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: October 29, 2012
%WINDIR%\TEMP\conhost.exe File name: conhost.exe
Size: 657.92 KB (657920 bytes)
MD5: dad74a8a848513c7ce73e674ab38aaee
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP
Group: Malware file
Last Updated: December 27, 2012
C:\Users\<username>\Desktop\AGIL2021\Arquivos nootebook\disco d\D\RAQUEL\AppData\Roaming\2 2\svchost.exe File name: svchost.exe
Size: 254.46 KB (254464 bytes)
MD5: f18f337f27c79e1f0cd4626d89dd3079
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\AGIL2021\Arquivos nootebook\disco d\D\RAQUEL\AppData\Roaming\2 2\svchost.exe
Group: Malware file
Last Updated: August 12, 2022
%SystemDrive%\Users\<username>\AppData\Roaming\hiazht.exe File name: hiazht.exe
Size: 4.72 MB (4727985 bytes)
MD5: 61ab4e0819f5e214be45de5e8f361170
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: May 13, 2013
%TEMP%\bitcoin-miner.exe File name: %TEMP%\bitcoin-miner.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%TEMP%\taskmgr.exe File name: %TEMP%\taskmgr.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%TEMP%\svchost.exe File name: %TEMP%\svchost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files
Loading...