The file SHELL.EXE is malware related.
You must delete the file SHELL.EXE immediately!
Delete the file SHELL.EXE without delay!
Kill the process SHELL.EXE and remove SHELL.EXE from the Windows startup.
Malware Analysis of SHELL.EXE
Full path on a computer: %Appdata%\Defender\Shell.exe
Detected by UnHackMe:
Item Name: Shell.exe
Author: Systemt
Related File: %APPDATA%\DEFENDER\SHELL.EXE
Type: Running Processes
Item Name: Skype.lnk
Author: Unknown
Related File: %APPDATA%\DEFENDER\USFT_EXT.EXE.VBS
Type: Startup Folder
Item Name: MACROMEDIA.EXE
Author: Systemt
Related File: %APPDATA%\DEFENDER\MACROMEDIA.EXE
Type: Multi AV Detected Files
Item Name: SHELL.EXE
Author: Systemt
Related File: %APPDATA%\DEFENDER\SHELL.EXE
Type: Multi AV Detected Files
Removal Results: Success
Number of reboot: 1
SHELL.EXE is known as:
Trojan.BitCoinMiner.crm, PUP.BitCoinMiner, Trojan.BitCoinMiner.bqvukc, RiskTool.BitCoinMiner.8ZWPwdavg5w, ApplicUnsaf.RiskTool.BitCoinMiner.CRM, SPR.BitCoinMiner.AS, a variant of Win32.BitCoinMiner.P, not-a-virus:RiskTool.BitCoinMiner
SHELL.EXE hash:
- MD5: b324f971c2357f5d0ebcf585473e8596
- %Appdata%\Defender
- %Appdata%\Defender\coinutil.dll
- %Appdata%\Defender\kill.bat
- %Appdata%\Defender\macromedia.exe
- %Appdata%\Defender\miner.dll
- %Appdata%\Defender\phatk.cl
- %Appdata%\Defender\phatk.ptx
- %Appdata%\Defender\put.vbs
- %Appdata%\Defender\Shell.exe
- %Appdata%\Defender\usft_ext.dll
- %Appdata%\Defender\usft_ext.exe.vbs
- %Recent%\Defender.lnk
- %Recent%\usft_ext.exe.lnk
- %Startup%\Skype.lnk