Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

SHELL.EXE is Trojan BitCoinMiner.crm

$
0
0

The file SHELL.EXE is malware related.
You must delete the file SHELL.EXE immediately!
Delete the file SHELL.EXE without delay!
Kill the process SHELL.EXE and remove SHELL.EXE from the Windows startup.

Malware Analysis of SHELL.EXE
Full path on a computer: %Appdata%\Defender\Shell.exe

Detected by UnHackMe:

Item Name: Shell.exe
Author: Systemt
Related File: %APPDATA%\DEFENDER\SHELL.EXE
Type: Running Processes

Item Name: Skype.lnk
Author: Unknown
Related File: %APPDATA%\DEFENDER\USFT_EXT.EXE.VBS
Type: Startup Folder

Item Name: MACROMEDIA.EXE
Author: Systemt
Related File: %APPDATA%\DEFENDER\MACROMEDIA.EXE
Type: Multi AV Detected Files

Item Name: SHELL.EXE
Author: Systemt
Related File: %APPDATA%\DEFENDER\SHELL.EXE
Type: Multi AV Detected Files

Removal Results: Success
Number of reboot: 1

SHELL.EXE is known as:

Trojan.BitCoinMiner.crm, PUP.BitCoinMiner, Trojan.BitCoinMiner.bqvukc, RiskTool.BitCoinMiner.8ZWPwdavg5w, ApplicUnsaf.RiskTool.BitCoinMiner.CRM, SPR.BitCoinMiner.AS, a variant of Win32.BitCoinMiner.P, not-a-virus:RiskTool.BitCoinMiner

SHELL.EXE hash:

  • MD5: b324f971c2357f5d0ebcf585473e8596
The file tries to download information from some web sites.
How to quickly detect SHELL.EXE presence?
Folders:
  • %Appdata%\Defender
Files:
  • %Appdata%\Defender\coinutil.dll
  • %Appdata%\Defender\kill.bat
  • %Appdata%\Defender\macromedia.exe
  • %Appdata%\Defender\miner.dll
  • %Appdata%\Defender\phatk.cl
  • %Appdata%\Defender\phatk.ptx
  • %Appdata%\Defender\put.vbs
  • %Appdata%\Defender\Shell.exe
  • %Appdata%\Defender\usft_ext.dll
  • %Appdata%\Defender\usft_ext.exe.vbs
  • %Recent%\Defender.lnk
  • %Recent%\usft_ext.exe.lnk
  • %Startup%\Skype.lnk


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>