Keygen_For_Fake_2021_11_by_ReverseCodez.exe Trojan CoinMiner Analysis

Trojan CoinMiner
Updated on 2024-03-15 (28 days ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.169.174
DB Version:2024-03-15 18:00:25

Trojan.Win32.CoinMiner.ca

CoinMiner is a type of malware that harnesses the victim's computer resources, primarily CPU and RAM, to engage in cryptocurrency mining, such as for Monero or Zcash. This malware establishes persistence by integrating an open-source mining tool into the system's startup routine without the user's consent. Advanced coin miners often employ techniques like timer configurations or CPU usage limits to operate discreetly and avoid detection.

FileKeygen_For_Fake_2021_11_by_ReverseCodez.exe
Checked2024-03-15 18:47:24
MD5f253e7e605ea76587fc448ceab9adbe8
SHA1bc41973fc11ce957bca3b42d619800405d6bb5bd
SHA25666b47d35aabce0caf153a3a34b0aff16792058e4e12eadd1c651022c55304e29
SHA5127e665edb656f16dea6755df35461a9d3bd941b2e3b80f22f9df5caf9d33be326423a52f71b4442cf8844280327a94483aee9df2dd456f6994b31a611d1578b67
Imphash332f7ce65ead0adfb3d35147033aabe9
File Size930816 bytes

Trojan.Win32.CoinMiner.ca Removal

Trojan.Win32.CoinMiner.ca Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.CoinMiner.ca without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

Portable Executable Info

Image Base:0x00400000
Entry Point:0x0049ab80
Compilation:1992-06-19 22:22:17
Checksum:0x00000000 (Actual: 0x000e5bc9)
OS Version:4.0
PEiD:PE32 executable (GUI) Intel 80386, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:8
Imports: kernel32, user32, advapi32, oleaut32, version, gdi32, ole32, comctl32, shell32, wininet, wsock32, netapi32,
Exports: 0
Resources:62

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
CODE 0x00001000 0x00099bec 0x00099c00 33fbe30e8a64654287edd1bf05ae7c8c 6.57
DATA 0x0009b000 0x00002e54 0x00003000 1f5e19e7d20c1d128443d738ac7bc610 4.85
BSS 0x0009e000 0x000011e5 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.idata 0x000a0000 0x00002a42 0x00002c00 21ff53180b390dc06e3a1adf0e57a073 4.92
.tls 0x000a3000 0x00000010 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.rdata 0x000a4000 0x00000039 0x00000200 a92cf494c617731a527994013429ad97 0.78
.reloc 0x000a5000 0x0000a980 0x0000aa00 dcd1b1c3f3d28d444920211170d1e8e6 6.67
.rsrc 0x000b0000 0x00038b30 0x00038c00 0ba46ec97947c6d1f87bfeed8d5224f6 6.90

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware