Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

AGFNAKJGAGASFASF.EXE is Trojan BitCoinMiner

$
0
0

The file AGFNAKJGAGASFASF.EXE is identified as a virus dropper.
The dropper AGFNAKJGAGASFASF.EXE is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.
The file AGFNAKJGAGASFASF.EXE loads into the computer memory and tries to connect to the dangerous web site.
Usually the AGFNAKJGAGASFASF.EXE dropper does not infect the files on the computer and does not replicate itself on other computers.
Kill the AGFNAKJGAGASFASF.EXE process and delete the file AGFNAKJGAGASFASF.EXE.

Malware Analysis of AGFNAKJGAGASFASF.EXE
Full path on a computer: %Appdata%\drivergpucpu\agfnakjgagasfasf.exe

Detected by UnHackMe:

AGFNAKJGAGASFASF.EXE
Default location: %Appdata%\drivergpucpu\agfnakjgagasfasf.exe

Removal Results: Success
Number of reboot: 1

AGFNAKJGAGASFASF.EXE is known as:

Trojan.BitCoinMiner, Tool.BtcMine.284, Trojan.BitCoinMiner.AX, a variant of Win32.BitCoinMiner.AX

AGFNAKJGAGASFASF.EXE hash:

  • MD5: 95eb67fe28484ec4318844dff6a4b465
The file tries to download information from some web sites.
How to quickly detect AGFNAKJGAGASFASF.EXE presence?
Folders:
  • %Appdata%\drivergpucpu
Files:
  • %Appdata%\drivergpucpu\agfnakjgagasfasf.exe
  • %Appdata%\drivergpucpu\libcurl-4.dll
  • %Appdata%\drivergpucpu\libwinpthread-1.dll
  • %Appdata%\drivergpucpu\zlib1.dll


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>