Gridinsoft Logo
File Icon

Taskhostw.exe Trojan CoinMiner Analysis

Technical Analysis

File Name taskhostw.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.211.174
Database Version 2025-03-18 22:00:32 UTC

Trojan.Win64.CoinMiner.ca

Malware family: CoinMiner

CoinMiner malware utilizes system resources including CPU and RAM for unauthorized cryptocurrency mining. It establishes persistence through startup integration and may use resource management techniques to avoid detection while mining currencies like Monero or Zcash.
N/A
Detection Rate
28,224,528
File Size (bytes)
2025-03-18
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
557fa65e3cee33dd71d1a87fc7383ec9
SHA1
bd81b0e7d182f38042c68ef3939d6dfc959eba0f
SHA256
8ff557591472698a4bae5391ace924a6aaef95c2a32f2ebcb204f888b852575d
SHA512
c30f26358e0d9954601a1f99984ff62fdd87f69b13086246c722ee38d9dcbba9cac0b0eaf416ef3d491db8c2bbd5f367fbbfd2539ea7bedbea10fee166889ea2
ImpHash
1cd069a1d0a6220306935daaf0c539a1

PE Analysis

Basic Information

Icon
Hash: e7ed9972eff118728ba27b08097c6f66
Fuzzy: 69ccbea4dbacd90b6f4eea4212a3791c
dHash: b4b0385e5859b2b4
Image Base 0x140000000
Entry Point 0x141de8160
Compilation Time 2024-12-11 18:48:26
Checksum 0x01af5dca (Actual: 0x01af5dca)
OS Version 5.2
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 18 libraries
Exports 0 functions
Resources 14 Resources
Sections 12 Sections

Version Information

CompanyName Realtek Semiconductor
FileDescription Realtek HD Audio
FileVersion 10.0.0.3
InternalName RtHDVBgProc.exe
LegalCopyright 2017 (c) Realtek Semiconductor. All rights reserved.
OriginalFilename taskhostw.exe
ProductName Realtek HD Audio
ProductVersion 10.0.0.3
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 733,992 bytes 391,680 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 63822DBA022DBD769E0996A738A4E01C
0x000b5000 213,508 bytes 60,928 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6141FE3F052E715ACA734115C4A6A1B7
0x000ea000 37,152 bytes 1,024 bytes 7.51 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 48AAB85CC5A6D54D9FACA8C207A01A7F
0x000f4000 28,488 bytes 16,896 bytes 7.66 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ AE3FD84C7ACF42FA4E67DF06AE5883E0
0x000fb000 22,159,360 bytes 22,158,336 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1B79314D35C069F5A33FA6E12F8119BC
0x0161d000 2,676 bytes 2,048 bytes 7.27 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ CD027850506445D3EFF06E6642E9A295
.idata 0x0161e000 4,096 bytes 1,536 bytes 3.25 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A85178E4512B39EF8D5847E4E2A53053
.tls 0x0161f000 4,096 bytes 512 bytes 0.28 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5842F1B5731D15CD6CD978773A87D1AC
.rsrc 0x01620000 376,320 bytes 376,320 bytes 2.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ A99887722C98176958CF9F7D400792FF
.themida 0x0167c000 7,782,400 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x01de8000 5,213,696 bytes 5,213,696 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 9DCE57530655A21F287FAC7792E94FD4
.reloc 0x022e1000 4,096 bytes 16 bytes 2.73 (Normal) IMAGE_SCN_MEM_READ BE8ECC38D1A4875319590210B287AAC9
Entropy Analysis Alert

6 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 14 (375,133 bytes)
Resource Type Count Total Size Percentage
RT_ICON 10 371,728 bytes
99.1%
RT_STRING 1 1,428 bytes
0.4%
RT_GROUP_ICON 1 146 bytes
0%
RT_VERSION 1 824 bytes
0.2%
RT_MANIFEST 1 1,007 bytes
0.3%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.CoinMiner.ca Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.CoinMiner.ca without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware