Home Possibly Unwanted Program CpuMiner

CpuMiner

Posted: April 10, 2015

Threat Metric

Ranking: 5,543
Threat Level: 1/10
Infected PCs: 47,034
First Seen: April 10, 2015
Last Seen: October 16, 2023
OS(es) Affected: Windows


CpuMiner is a Potentially Unwanted Program (PUP) that may enter silently and take advantage of the user's machine for the benefits of its developers. This questionable application is a BitCoin miner. CpuMiner uses the CPU and the video card of the computer to maintain the infrastructure of this cryptocurrency. As a universal rule, the owner of the device should receive certain commissions for keeping the network alive. However, this PUP is not created to share the profits with you. All revenue will go towards its developers, so they are virtually taking advantage of your machine. The security researchers have confirmed that CpuMiner may travel via the well-known bundling method. CpuMiner may be deployed to your system by third-party freeware. If you conduct the setup procedure via the 'Quick' menu, you may receive no clues whatsoever that CpuMiner is about to enter. Fortunately, if you rely on the 'Advanced' menu, you may be able to uncheck its box manually. The description that you may notice is pretty brief – it says CpuMiner is a BitCoin miner. However, some users may not expect CpuMiner to have such an unfavorable impact on their machines, so they may still agree to load it. This suspicious application may use a significant part of the available resources. The experts have determined that CpuMiner may seize for its processes over 30% of your CPU's capabilities and graphic's card power. This means that you may be unable to use that portion of their potential for other purposes. Your applications may start running sluggishly if they launch at all. The possible higher resource consumption means a higher electricity consumption as well, which may mean a higher bill. It is important to note that CpuMiner functions whenever your PC is switched on. Your hardware will have no time to 'rest' and cool itself, so the PC may start generating a lot of heat. This issue may damage some components. If your machine starts working sluggishly, you should run a full system scan with a powerful security utility to delete CpuMiner immediately.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\RarSFX0\keygen-pr.exe File name: keygen-pr.exe
Size: 1.82 MB (1827316 bytes)
MD5: 3a82e425e5086fd8072c5b1862b8906f
Detection count: 379
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\RarSFX0\keygen-pr.exe
Group: Malware file
Last Updated: March 18, 2023
C:\Windows.old\Windows\System32\cpuminer-gw64.exe File name: cpuminer-gw64.exe
Size: 1.41 MB (1413920 bytes)
MD5: aeed08f2af685a9d1ca9436f9ba4c80b
Detection count: 164
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows.old\Windows\System32\cpuminer-gw64.exe
Group: Malware file
Last Updated: June 11, 2021
C:\Users\<username>\Downloads\New folder\BACK UPS 11-2018\Easy_Tether_Lite_v1_1_keygen.exe\Easy_Tether_Lite_v1_1_keygen\keygen-pr.exe File name: keygen-pr.exe
Size: 1.83 MB (1830196 bytes)
MD5: c9a8153177c6785ad657c4884737b51c
Detection count: 150
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\New folder\BACK UPS 11-2018\Easy_Tether_Lite_v1_1_keygen.exe\Easy_Tether_Lite_v1_1_keygen\keygen-pr.exe
Group: Malware file
Last Updated: March 12, 2023
D:\download\Rebelbetting.3.5.1010.2904.keygen.exe\Rebelbetting.3.5.1010.2904.keygen\keygen-p.exe File name: keygen-p.exe
Size: 1.74 MB (1747908 bytes)
MD5: 57107b565d0c3c6ca2fafc394de8d78c
Detection count: 138
File type: Executable File
Mime Type: unknown/exe
Path: D:\download\Rebelbetting.3.5.1010.2904.keygen.exe\Rebelbetting.3.5.1010.2904.keygen\keygen-p.exe
Group: Malware file
Last Updated: February 1, 2023
%WINDIR%\system32\cpuminer-gw64.exe File name: cpuminer-gw64.exe
Size: 4.24 MB (4240616 bytes)
MD5: 50e7271bca167d94a4bb76db523a2302
Detection count: 129
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: May 10, 2016
C:\Users\<username>\AppData\Local\Temp\RarSFX0\keygen-p.exe File name: keygen-p.exe
Size: 1.74 MB (1749332 bytes)
MD5: 9708eec3c47ea61785ba580b30ab00c3
Detection count: 112
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\RarSFX0\keygen-p.exe
Group: Malware file
Last Updated: January 14, 2023
%TEMP%\RarSFX0\keygen-pr.exe File name: keygen-pr.exe
Size: 62.46 KB (62464 bytes)
MD5: 756777e398ffb7186312cb456ef7d1fb
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX0
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX0\keygen-p.exe File name: keygen-p.exe
Size: 1.75 MB (1750116 bytes)
MD5: 793370bc0afa658e9b7fe4cc2df8b511
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX0
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX1\key.exe File name: key.exe
Size: 62.46 KB (62464 bytes)
MD5: f1ce38d20524a4235bec0505c3b0b27d
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX1
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX0\keygen-pr.exe File name: keygen-pr.exe
Size: 62.46 KB (62464 bytes)
MD5: 51ed9624b03c9297695894fce06fa14b
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX0
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX1\key.exe File name: key.exe
Size: 62.46 KB (62464 bytes)
MD5: 244819b5d6db5fe1975ac06609c18b7d
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX1
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX0\key.exe File name: key.exe
Size: 62.46 KB (62464 bytes)
MD5: ee75153aa34afe04f17d0b8df75075a1
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX0
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX1\key.exe File name: key.exe
Size: 62.46 KB (62464 bytes)
MD5: c446bf78e7407da243b7176ef1786fb2
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX1
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX0\keygen-pr.exe File name: keygen-pr.exe
Size: 62.46 KB (62464 bytes)
MD5: 77409e0a877953953d937d07d17a763f
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX0
Group: Malware file
Last Updated: February 25, 2016
C:\Users\<username>\AppData\Local\Microsoft\Windows\FileHistory\Data\2541\C\Users\<username>\Downloads\GetFLV.Pro.5.3.keygen.exe\keygen-p.exe File name: keygen-p.exe
Size: 1.74 MB (1747924 bytes)
MD5: 71224863f6cbf8e81d10034774e4d192
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Microsoft\Windows\FileHistory\Data\2541\C\Users\<username>\Downloads\GetFLV.Pro.5.3.keygen.exe\keygen-p.exe
Group: Malware file
Last Updated: February 14, 2023
C:\Users\<username>\AppData\Local\Temp\RarSFX2\key.exe File name: key.exe
Size: 59.9 KB (59904 bytes)
MD5: 7a45213a8d3887fd524b003ca8f37dec
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\RarSFX2\key.exe
Group: Malware file
Last Updated: August 8, 2021
%TEMP%\RarSFX12\key.exe File name: key.exe
Size: 59.9 KB (59904 bytes)
MD5: 0c81d09d14b2e3ea95c20c7d83dac801
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX12
Group: Malware file
Last Updated: August 9, 2020
%TEMP%\RarSFX2\key.exe File name: key.exe
Size: 62.46 KB (62464 bytes)
MD5: df1990f9713db81afcd78e3d87dedf40
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX2
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX0\keygen-p.exe File name: keygen-p.exe
Size: 1.74 MB (1749316 bytes)
MD5: 50fc79d79892c762c41108314b7c9f67
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX0
Group: Malware file
Last Updated: April 1, 2020
%TEMP%\RarSFX2\key.exe File name: key.exe
Size: 59.9 KB (59904 bytes)
MD5: 941a87b716aa7358ba05fb9375ab0630
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX2
Group: Malware file
Last Updated: April 10, 2020
%TEMP%\RarSFX2\key.exe File name: key.exe
Size: 62.46 KB (62464 bytes)
MD5: fc8880c7e05a2affa9e358e74ffbab8a
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX2
Group: Malware file
Last Updated: February 25, 2016
%TEMP%\RarSFX0\key.exe File name: key.exe
Size: 77.82 KB (77824 bytes)
MD5: dfc47e0c9f06af5c26a587e205bb7887
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX0
Group: Malware file
Last Updated: March 22, 2020

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%TEMP%\cpuminer\cpm.exe%TEMP%\cpuminer\cpuminer-conf.json%TEMP%\mdi064.dll%WINDIR%\System32\cpuminer-conf.jsonHKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpuminerHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}cpuminergpuminer

Additional Information

The following directories were created:
%APPDATA%\vnlgp%appdata%\cpuminer
Loading...