Trojan

Trojan.Win32.Miner.asuxf (file analysis)

Malware Removal

The Trojan.Win32.Miner.asuxf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.asuxf virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Win32.Miner.asuxf?


File Info:

crc32: B3F1E60B
md5: 9cfb02f7e6163ab2f240e110158a3af3
name: svchosst.exe
sha1: 9d4fd08694cc41c67c3389280fa418360bfd4fb1
sha256: a80e09ff157994cc4c951f7ddff7a777091a3c26c1d974b9e92b0b7b5869512b
sha512: 54f95b3db436720689aff02af4ac48a90cd1a8539f81f6e950f1629599bac90a4086588a2992db08a60b44e47d83222c64528be66264900b467166ca5458b3ca
ssdeep: 49152:LSgqe1XzEm4aUC0XuOSc/ZQOViIthXH16qGWsH45ZmIK9paWePicQOH/6:+0G/ZQOViIthX7GWzmIKfaKu6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: Miner208
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Miner208 Application
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: Miner208 MFC Application
OriginalFilename: Miner208.EXE
Translation: 0x0409 0x04b0

Trojan.Win32.Miner.asuxf also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanDropped:Trojan.GenericKD.43408864
FireEyeGeneric.mg.9cfb02f7e6163ab2
Qihoo-360Win32/Virus.RiskTool.435
McAfeeGenericRXAA-FA!9CFB02F7E616
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 0055fa291 )
BitDefenderDropped:Trojan.GenericKD.43408864
K7GWAdware ( 0055fa291 )
CrowdStrikewin/malicious_confidence_80% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Miner-DM [Trj]
ClamAVWin.Coinminer.Generic-7151253-0
GDataDropped:Trojan.GenericKD.43408864
KasperskyTrojan.Win32.Miner.asuxf
AlibabaTrojan:Win32/Miner.6671820f
AegisLabTrojan.Win32.Miner.4!c
TencentWin32.Trojan.Miner.Hytv
Ad-AwareDropped:Trojan.GenericKD.43408864
SophosXMRig Miner (PUA)
F-SecureHeuristic.HEUR/AGEN.1134782
DrWebTrojan.DownLoader32.59978
TrendMicroTROJ_GEN.R03BC0WFU20
EmsisoftDropped:Trojan.GenericKD.43408864 (B)
IkarusPUA.CoinMiner
CyrenW64/Trojan.QMIV-1379
JiangminRiskTool.BitCoinMiner.lew
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1134782
MAXmalware (ai score=87)
Antiy-AVLRiskWare[RiskTool]/Win32.BitMiner
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2965DE0
ZoneAlarmTrojan.Win32.Miner.asuxf
MicrosoftTrojan:Win32/CoinMiner.C!cl
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win32.CoinMiner.R327911
BitDefenderThetaGen:NN.ZexaF.34130.Js0@aK0BQbfj
ALYacDropped:Trojan.GenericKD.43408864
VBA32BScope.Trojan.Miner
MalwarebytesRiskWare.BitCoinMiner
PandaTrj/CI.A
ESET-NOD32a variant of Win64/CoinMiner.QG potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R03BC0WFU20
RisingTrojan.Miner!8.EA1 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Miner
AVGWin32:Miner-DM [Trj]
Cybereasonmalicious.7e6163
Paloaltogeneric.ml

How to remove Trojan.Win32.Miner.asuxf?

Trojan.Win32.Miner.asuxf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment