Home Malware Programs Trojans Skodna.BitCoinMiner.AD

Skodna.BitCoinMiner.AD

Posted: October 10, 2012

Threat Metric

Ranking: 9,269
Threat Level: 9/10
Infected PCs: 19,126
First Seen: October 10, 2012
Last Seen: September 27, 2023
OS(es) Affected: Windows

Skodna.BitCoinMiner.AD is a Trojan that exploits an infected computer's resources to generate fraudulent digital currency. Because allowing Skodna.BitCoinMiner.AD to remain on your PC encourages destructive financial activity, Skodna.BitCoinMiner.AD should be removed quickly and by anti-malware products that are capable of detecting obfuscated PC threats. BitCoin miner Trojans like Skodna.BitCoinMiner.AD are often associated with system instability, although Skodna.BitCoinMiner.AD may be configured to avoid such side effects, and deleting Skodna.BitCoinMiner.AD by manual methods has been reported to be extremely difficult.

Why Your Computer is the Pickaxe Skodna.BitCoinMiner.AD Uses to Dig for Wealth

Skodna.BitCoinMiner.AD is designed to avoid detection by visual means and is installed by deceptive methods. SpywareRemove.com malware researchers are inclined to point to drive-by-downloads by Blacole or spammed links from social networking programs as likely infection vectors for Skodna.BitCoinMiner.AD, given their recent popularity, although Skodna.BitCoinMiner.AD also may be installed by other means. Trojan downloaders from the Comine family often include BitCoin miners like Skodna.BitCoinMiner.AD in their payloads.

While Skodna.BitCoinMiner.AD lurks in the background, unseen, Skodna.BitCoinMiner.AD generates money in BitCoin – an online currency that provides convenient digital money to the tune of one BitCoin equating to ten USD. While generating fake BitCoins is a popular pastime for several types of Trojans, SpywareRemove.com malware experts have taken notice of Skodna.BitCoinMiner.AD as a recent PC threat, with Skodna.BitCoinMiner.AD-related attacks being seen this month of 2012.

The Challenge in Digging Skodna.BitCoinMiner.AD out of Your Computer

As far as Trojans go, Skodna.BitCoinMiner.AD is a relatively intractable specimen that resists even basic attempts at removal from established brands of anti-malware products. To delete Skodna.BitCoinMiner.AD safely, SpywareRemove.com malware analysts also recommend that you make an effort to disable Skodna.BitCoinMiner.AD and all PC threats related to Skodna.BitCoinMiner.AD by tactics as noted below:

  • If possible, boot your computer from a separate OS that's loaded onto a clean USB device. This device also should be scanned to be certain that malware related to Skodna.BitCoinMiner.AD Trojans are unable to infect it.
  • Switch Windows to Safe Mode by tapping F8 during the boot process.

These steps will disable most types of malicious software and allow you to remove Skodna.BitCoinMiner.AD with appropriate anti-malware scans. As a Trojan that may have recent updates or variants, Skodna.BitCoinMiner.AD should be deleted by anti-malware scanners that have, themselves, been given full database updates.

BitCoin-generating attacks by Skodna.BitCoinMiner.AD may cause serious instability for your PC. Programs may crash or be sluggish, user interfaces may be unresponsive, and resources like your CPU and RAM may be much lower than normal. Skodna.BitCoinMiner.AD, like some other types of BitCoin-mining Trojans, also may be used for other attacks that can harm your PC in diverse ways, such as by creating backdoor vulnerabilities or installing other malware. Naturally, removing Skodna.BitCoinMiner.AD should be done as expediently as is possible for your PC's sake.

Aliases

Skodna.BitCoinMiner.AD [AVG]W32/StartPage.OKR [Fortinet]Trojan.StartPage.42828 [DrWeb]Trojan.Dropper-31300 [ClamAV]Win32/StartPage.OKR [NOD32]Artemis!C8C675C8F142 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\$Recycle.Bin\S-1-5-21-3541193035-3141088245-1877753966-1002\$RN6UMF7.exe File name: $RN6UMF7.exe
Size: 1.64 MB (1640466 bytes)
MD5: c8c675c8f14293c911444f2d403f2c2d
Detection count: 1,211
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\$Recycle.Bin\S-1-5-21-3541193035-3141088245-1877753966-1002\$RN6UMF7.exe
Group: Malware file
Last Updated: October 2, 2023
Loading...