Threat Database Trojans Trojan.Bitcoinminer.BD

Trojan.Bitcoinminer.BD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 7,609
Threat Level: 80 % (High)
Infected Computers: 4,418
First Seen: September 1, 2021
Last Seen: July 15, 2026
OS(es) Affected: Windows

The detection of Trojan.Bitcoinminer.BD on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's resources for malicious purposes, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Bitcoinminer.BD?

Trojan.Bitcoinminer.BD is a type of Trojan horse malware that is primarily used for cryptocurrency mining. It is designed to secretly use your computer's processing power to mine for cryptocurrencies, such as Bitcoin, without your knowledge or consent. This can lead to significant system slowdowns, increased electricity bills, and reduced overall performance.

How Trojan.Bitcoinminer.BD Operates

Trojan.Bitcoinminer.BD typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can connect to a command and control server to receive instructions and transmit stolen data. The malware may also download additional components or updates to enhance its functionality and evade detection. It's crucial to note that Trojan.Bitcoinminer.BD can be difficult to detect, as it may not exhibit obvious symptoms or display any visible signs of infection.

Symptoms of Infection

While Trojan.Bitcoinminer.BD may not always display noticeable symptoms, some common signs of infection include:

  • Unexplained increases in CPU or GPU usage
  • Slow system performance or freezes
  • Overheating of the computer or laptop
  • Unusual network activity or data transfers
  • Increased electricity bills or power consumption

If you've noticed any of these symptoms, it's essential to take immediate action to scan your system and remove the malware.

How to Remove Trojan.Bitcoinminer.BD

To remove Trojan.Bitcoinminer.BD from your system, follow these steps:

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full system scan to detect and remove the malware
  3. Uninstall any suspicious programs or applications that may be related to the malware
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your computer and perform another full system scan to ensure the malware has been completely removed

It's crucial to be thorough and patient during the removal process to ensure that all components of the malware are eliminated.

Conclusion

The removal of Trojan.Bitcoinminer.BD requires careful attention to detail and a comprehensive approach. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your computer and data safe. Remember to always be cautious when installing software, avoid suspicious links or attachments, and keep your operating system and security software up to date to minimize the risk of malware infections.

Analysis Report

General information

Family Name: Trojan.Bitcoinminer.BD
Signature status: No Signature

Known Samples

MD5: d8d38161c785c6edd1d613fe4170dfff
SHA1: 70f8d74b973cceb00939d08187db80ab5ce04fe5
SHA256: 1B98A59CD2B30C7C1C6BE409BEDCF7949C9648B0739B294AA2DD22A0FBD84DC1
File Size: 323.07 KB, 323072 bytes
MD5: f51ff24f76b6a73a540f2b2e37f7a61d
SHA1: ddedcd0709040c55a18fe7b881f8fa3d35aa4b5a
SHA256: 04C674525A24930271C69E01DDD2D7B65BC7791360577C9BA61E70043C713C22
File Size: 85.50 KB, 85504 bytes
MD5: 4d84165f8ec03d882096caa111d4cc3a
SHA1: 7c67b3a1c1e7fc4a75049ea282ea820381296c10
SHA256: 0F23213390B28873BCED1551E34B1DF8132B9FF78B953E83E13D932E14191595
File Size: 76.29 KB, 76288 bytes
MD5: b40f928a690cfa094e90c32df4465474
SHA1: cb04cc542b15ba5a2ed93b3c7c2479e52b301cec
SHA256: 28871AD9C698E531CAE840A5296BD2A1FDDCD291E3EADAAFFFB51806B7DDA42B
File Size: 51.71 KB, 51712 bytes
MD5: afcfb3822edb223a1457e4c52ba4c87e
SHA1: dec9bc0209c98dd13295459447f94c2f21740ced
SHA256: 790001BA70A9A32F4192FE64EF63386218511DAD34A335BAEF2F0534CBA0E1EB
File Size: 27.14 KB, 27136 bytes
Show More
MD5: eee126d29a950cb480c76d849a7c9532
SHA1: 8c04c859a0ba8eca8e58cfb0cce139051fd31dcf
SHA256: F9FFF21DEC20696BBF65D7C540DDFDCB247C12BAE6DB26993B6801F44797EA8C
File Size: 99.33 KB, 99328 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Global Pubg Setup
  • Supermercado Unico
File Description
  • Actualizador Sistemas Unico
  • Global Pubg Setup
File Version 1,0,0,0
Internal Name
  • ASU
  • Global Pubg Setup
Legal Copyright
  • 2014
  • www.gameprohack.com
Product Name
  • ASU
  • Global Pubg Setup
Product Version 1.0.0.0

File Traits

  • 2+ executable sections
  • Installer Version
  • No Version Info
  • packed
  • x64

Block Information

Total Blocks: 183
Potentially Malicious Blocks: 89
Whitelisted Blocks: 94
Unknown Blocks: 0

Visual Map

x x x x x 0 0 x 0 x 0 x x 0 x x 0 x x 0 x 0 x 0 x x 0 x 0 x x 0 0 0 x x x 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 x 0 x x 0 0 x x 0 0 x x x 0 0 0 0 x 0 x x x 0 0 x 0 x 0 0 0 0 x 0 0 0 x x x x x x 0 0 0 x 0 0 x 0 0 0 x x 0 x 0 x 0 0 0 x x 0 x 0 0 x 0 0 0 x 0 x x x 0 0 0 x 0 x x 0 x x 0 x x x x x x 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 x 0 x x x 0 x x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.OCF
  • Bitcoinminer.BD

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\28ff.tmp\woact.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\2fa3.tmp\actualizador.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\54f9.tmp\global pubg kurulum.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\5a36.tmp\accès direct roamig (mozilla).bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\a6ca.tmp\decextx64.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\a9d7.tmp\high.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\againstwork\decext.exts Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\againstwork\decext.exts Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 륎翑⛵ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\explorer.exe 䩓翽⛵ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 瀛䋬沏ǜ RegNtPreCreateKey
HKCU\software\tencent\mobilegamepc::adbdisable RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 垸⠝漍ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ࠐ⠮漍ǜ RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy�ރeeVs} kP~ ��1��ee�����1��ie��r>�ve�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �i' +� xy��Bx#@�$¨1HO9�@V�@��g��rnJu�~y�^���P��ރ�����|��7�b:�������a ������ [�m�Ù���p�'��IV�t����$�`�(!��o��j�`�V�P�����zH�Q]��@K�B'i RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ҉唥苳ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 赈售苳ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 懇韧褮ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 韰褮ǜ RegNtPreCreateKey
HKCU\local settings\muicache\1b\52c64b7e::@c:\windows\system32\ndfapi.dll,-40001 Windows Network Diagnostics RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe �3�7�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ;�7�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ,k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~� % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee+Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
Show More
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects

31 additional items are not displayed above.

Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Terminate
  • TerminateProcess
Network Winsock2
  • WSAStartup
Network Winsock
  • freeaddrinfo
  • getaddrinfo
Network Icmp
  • IcmpCreateFile
  • IcmpSendEcho2Ex

Shell Command Execution

"\5A36.tmp\Acc�s direct Roamig (Mozilla).bat"
C:\WINDOWS\explorer.exe explorer.exe "C:\Users\Eizoenkm\AppData\Roaming"
"\54F9.tmp\Global Pubg Kurulum.bat"
C:\WINDOWS\system32\reg.exe reg add "HKCU\Software\Tencent\MobileGamePC" /v AdbDisable /t REG_DWORD /d 0 /f
open \2FA3.tmp\actualizador.bat
Show More
WriteConsole:
WriteConsole: c:\users\user\do
WriteConsole: C:
WriteConsole: cd
WriteConsole: \archivos de pr
WriteConsole: The system canno
WriteConsole: start
WriteConsole: ASU.exe
WriteConsole: exit
open \28FF.tmp\woact.bat
C:\WINDOWS\system32\PING.EXE ping -n 12 127.0.0.1
open \A9D7.tmp\high.bat
open \A6CA.tmp\decextx64.bat
WriteConsole: del
WriteConsole: C:\Windows\Agai
WriteConsole: echo
WriteConsole:
WriteConsole: 1>
WriteConsole: >
WriteConsole: C:\Windows\Again
WriteConsole: copy
WriteConsole: C:\Windows\cry

Related Posts

Trending

Most Viewed

Loading...