IMG001.exe Trojan CoinMiner Analysis

Trojan CoinMiner
Updated on 2024-04-27 (23 days ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.173.174
DB Version:2024-04-27 18:00:20

Trojan.Win32.CoinMiner.vb

CoinMiner is a type of malware that harnesses the victim's computer resources, primarily CPU and RAM, to engage in cryptocurrency mining, such as for Monero or Zcash. This malware establishes persistence by integrating an open-source mining tool into the system's startup routine without the user's consent. Advanced coin miners often employ techniques like timer configurations or CPU usage limits to operate discreetly and avoid detection.

FileIMG001.exe
Checked2024-04-27 18:26:34
MD510ed86a8d2f003bfce575296f7712772
SHA124399b552c47ea19c42015b423fc277e64e4b79b
SHA256d96763a30957d23c7f728c53a24168d21e28147ebcd3e2b26033d7cfdced78c5
SHA5123d42b8f639eb958002c3342861dd093263a5e057cb8ed6e869e344b86059d4d7877519f17af3308d741b4561263407d31961ccb69175eb8500a9f3ce40d7e3dd
Imphash7fa974366048f9c551ef45714595665e
File Size3414085 bytes

Trojan.Win32.CoinMiner.vb Removal

Trojan.Win32.CoinMiner.vb Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.CoinMiner.vb without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

Portable Executable Info

1f72cfbc50a07d177fb3e446a59df406
8178acc1f236273c1fd3b8ede6629310
beb4b6b6b6b6b030
Image Base:0x00400000
Entry Point:0x004030de
Compilation:2009-12-05 22:51:50
Checksum:0x00000000 (Actual: 0x0034ba53)
OS Version:4.0
PEiD:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Sign:The PE file does not contain a certificate table.
Sections:5
Imports: KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, VERSION,
Exports: 0
Resources:15

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x00005a2c 0x00005c00 6d2ac949e509365289077f57a2394cc2 6.45
.rdata 0x00007000 0x00001190 0x00001200 a2c7710fa66fcbb43c7ef0ab9eea5e9a 5.18
.data 0x00009000 0x003bc798 0x00000400 4fd7359a00726630d103f26d54f0c156 4.61
.ndata 0x003c6000 0x00040000 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.rsrc 0x00406000 0x0000f160 0x0000f200 4bc950a2bcc82be430135f9e604ac420 6.88

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware