Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

PROCESSUSAGE.EXE is Trojan BtcMine.356

$
0
0

Is the file PROCESSUSAGE.EXE located on your computer? Then your computer is infected.
We do suggest you should remove PROCESSUSAGE.EXE from your computer as soon as possible.
PROCESSUSAGE.EXE is Trojan/Backdoor.
Kill the process PROCESSUSAGE.EXE and remove PROCESSUSAGE.EXE from the Windows startup.

Malware Analysis of PROCESSUSAGE.EXE
Full path on a computer: %Program Files%\DoubleOptMedia\ProcessUsage.exe

Detected by UnHackMe:

PROCESSUSAGE.EXE
Default location: %Program Files%\DoubleOptMedia\ProcessUsage.exe

Removal Results: Success
Number of reboot: 1

PROCESSUSAGE.EXE is known as:

Trojan.BtcMine.356, Trojan.MalPacked, Win32.MediaMine.A, Win32.Trojan.8b6

PROCESSUSAGE.EXE hash:

  • MD5: ac7440d4880d578c09ac9f459dd90919
The file tries to download information from some web sites.
How to quickly detect PROCESSUSAGE.EXE presence?
Registry:
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DoubleOptMedia11.041.44\DisplayName: “DoubleOptMedia”
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DoubleOptMedia11.041.44\UninstallString: “”%Program Files%\DoubleOptMedia\uninstall.exe” “/U:%Program Files%\DoubleOptMedia\Uninstall\uninstall.xml”"
Folders:
  • %Program Files%\DoubleOptMedia
  • %Program Files%\DoubleOptMedia\Uninstall
Files:
  • %Program Files%\DoubleOptMedia\deinstaller.exe
  • %Program Files%\DoubleOptMedia\Installer.exe
  • %Program Files%\DoubleOptMedia\libcurl.dll
  • %Program Files%\DoubleOptMedia\libeay32.dll
  • %Program Files%\DoubleOptMedia\libidn-11.dll
  • %Program Files%\DoubleOptMedia\libpdcurses.dll
  • %Program Files%\DoubleOptMedia\lua5.1.dll
  • %Program Files%\DoubleOptMedia\opencl.cl
  • %Program Files%\DoubleOptMedia\OpenCL.dll
  • %Program Files%\DoubleOptMedia\ProcessUsage.exe
  • %Program Files%\DoubleOptMedia\pthreadGC2.dll
  • %Program Files%\DoubleOptMedia\ssleay32.dll
  • %Program Files%\DoubleOptMedia\Uninstall\IRIMG1.JPG
  • %Program Files%\DoubleOptMedia\Uninstall\IRIMG2.JPG
  • %Program Files%\DoubleOptMedia\Uninstall\uninstall.dat
  • %Program Files%\DoubleOptMedia\Uninstall\uninstall.xml
  • %Program Files%\DoubleOptMedia\uninstall.exe
  • %Program Files%\DoubleOptMedia\VideoUsage.exe
  • %Program Files%\DoubleOptMedia\zlib1.dll


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>