Home Malware Programs Trojans Trojan.CoinStealer

Trojan.CoinStealer

Posted: June 28, 2016

Threat Metric

Ranking: 4,541
Threat Level: 8/10
Infected PCs: 27,011
First Seen: June 28, 2016
Last Seen: March 3, 2025
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0509[1].exe File name: 0509[1].exe
Size: 2.26 MB (2265088 bytes)
MD5: cfa37459c88481113b827eeba9b1bb77
Detection count: 649
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0509[1].exe
Group: Malware file
Last Updated: March 15, 2024
%APPDATA%\Windows View Invoker\iexplorer.exe File name: iexplorer.exe
Size: 282.62 KB (282624 bytes)
MD5: 99915467d9cc23541273acddf52a72f5
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Windows View Invoker
Group: Malware file
Last Updated: October 25, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\Switcher\switcher.exe%APPDATA%\Switcher\uninstall.exe%WINDIR%\debug\lsmose{1,2}.exe%WINDIR%\help\lsmose{1,2}.exe

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\AMD\Microsoft%ALLUSERSPROFILE%\NVIDIAorpofiles%APPDATA%\Web View Invoker%APPDATA%\Windows Script Invoker%APPDATA%\Windows View Invoker
Loading...