MINER.EXE – trojan BitCoinMiner

We checked some samples of MINER.EXE and detected the file MINER.EXE as threat.
Remove the MINER.EXE file from your computer right now.
Removal tool: http://www.unhackme.com

Malware Analysis of “MINER.EXE”
Executed: ism2.exe
Removed: miner.exe. Full path: C:\Documents and Settings\Administrator\Local Settings\Temp\miner.exe


Detected by UnHackMe:

Item Name: CPU Config
Author: Microsoft
Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\UDPCONMAIN.EXE
Type: Registry Run

Item Name: miner.exe
Author: Ufasoft
Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\MINER.EXE
Type: Running Processes

Removal Results: Success
Number of reboot: 1


MINER.EXE is known as::
SPR/Tool.BitCoinMiner.a.1


MINER.EXE hash:
MD5: b4986e5d94d0e5723eea640a6735769
SHA1: ab3272d5ef1038bf3d336d2b033b813403a9ff2
SHA256: b2b026f8d00b02ff75f05cbf322e4f4b85fb609cddd93bebf17014914b90df9



How to quickly detect MINER.EXE presence?

Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\CPU Config: “C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\udpconmain.exe”

Files:
C:\Documents and Settings\Administrator\Local Settings\Temp\miner.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\udpconmain.exe


Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com

Fix it immediately!

Free Download

UnHackMe removes malware invisible for your antivirus!

Leave a Reply