Threat Database Trojans Trojan.Coinminer.GCE

Trojan.Coinminer.GCE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 4,456
Threat Level: 80 % (High)
Infected Computers: 4,942
First Seen: August 31, 2021
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.GCE indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to operate covertly, making it challenging to detect without the aid of security software. Understanding the nature and behavior of Trojan.Coinminer.GCE is crucial in taking the appropriate steps to remove it and prevent future infections.

What Is Trojan.Coinminer.GCE?

Trojan.Coinminer.GCE is identified as a Trojan-type threat, which typically involves malicious software disguising itself as legitimate to gain unauthorized access to a computer system. The name suggests it might be involved in unauthorized cryptocurrency mining, but without specific details, it's essential to approach removal with a broad strategy that covers various potential malicious activities.

How Trojan.Coinminer.GCE Operates

Trojan-type threats like Trojan.Coinminer.GCE often exploit vulnerabilities in software or trick users into installing them. Once installed, they can perform a variety of malicious actions, including but not limited to, data theft, unauthorized access to system resources, and in the case of coinminers, using the system's resources for cryptocurrency mining without the user's consent. These operations can significantly impact system performance and security.

Symptoms of Infection

Symptoms of an infection can vary widely but may include noticeable slowdowns in system performance, increased power consumption, and potentially, unusual network activity. Since Trojans can be designed to perform a wide range of malicious activities, symptoms might not always be immediately apparent. Regular system monitoring and the use of reputable security software are key to early detection.

  • Unexplained increases in CPU or GPU usage
  • Slow system performance
  • Increased electricity bills due to higher power consumption
  • Unusual or unexpected network traffic

How to Remove Trojan.Coinminer.GCE

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all associated files and registry entries.
  3. Uninstall any recently installed or suspicious programs that could be related to the infection.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and perform another full scan to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Coinminer.GCE requires a systematic approach to ensure all components of the malware are eliminated from the system. It's also crucial to adopt preventive measures, such as keeping software up to date, using strong antivirus programs, and being cautious with email attachments and downloads from the internet. By understanding the potential risks and taking proactive steps, users can significantly reduce the likelihood of future malware infections and protect their systems and personal data.

Analysis Report

General information

Family Name: Trojan.Coinminer.GCE
Signature status: No Signature

Known Samples

MD5: 17bdfc45f5a581ac7c9ed238dd974024
SHA1: 79d513764556d9a636f335e19dd301d0e3c90103
SHA256: F30A544A8C8488193A413715EA03C8E46B31668EA392BD818FE47D6015488E06
File Size: 3.04 MB, 3036768 bytes
MD5: 85f1a5840467be3fc03277e1944f4a2f
SHA1: 6de4eca8bc9fa4bbb83d90e099087ec455a28634
SHA256: 3E6BA0C9CDF4DCC9A6ACF6EE1378F01D0441332B43F4CCB69C13F24E956954CA
File Size: 2.21 MB, 2209792 bytes
MD5: 046696eb8755c55584ee79c58519bade
SHA1: d8e1d7d60f2fbb6a69beae17bd469b0e87c5a63f
SHA256: 75A34F6AAACD13CE4483F71CF27AA8331149D2C5C581EA6E407A06251960013B
File Size: 2.21 MB, 2209792 bytes
MD5: bb9c780d72b779e6b057743c58960ba1
SHA1: 16781c539553da902802fe5190053e594fa5f374
SHA256: 26CE051A69CBF092EBE0AF0129229A8658CE7B83D73077A775DC2B610BD2DED2
File Size: 2.21 MB, 2209792 bytes
MD5: b7725050baa62373aca2893dbdd79a8b
SHA1: 99e7e45fbf091c9459f71ad8a9ba7eb90874aae5
SHA256: D7B36848A423F1B79B137934A9F0A12B3D521C80F0B8BEB3293ABD143947ADF4
File Size: 2.21 MB, 2209792 bytes
Show More
MD5: 0d474f40a8c1ccd7db630ee52c86b009
SHA1: 9dcad50444bec91f4c271fb46169c74a1fe74023
SHA256: A3B0EF0D6EEEE41B70D69EB843A3F5CE1794BDEFBEE1C25997272319CAD3A30F
File Size: 2.21 MB, 2209280 bytes
MD5: 107352e0d221e654a73e2f2708f5c2d2
SHA1: 7355f11d779e0c42bcb2dbc79c9ea510df33738c
SHA256: 83E393103B5960B6D139F3FF8306B83E5190E43D53C12713D91AF746438D16FF
File Size: 2.23 MB, 2230272 bytes
MD5: 19492dbf8183cf5d525ec71066eb878b
SHA1: b722899696a022d887227cd3e1a2c38a4573aa3b
SHA256: 998036CFC1D3FD3D03CABD89E048704167E0787C141A9DFA6549B8575B5BA427
File Size: 1.67 MB, 1669008 bytes
MD5: 843fb109eb1215c532721dd07bbf4b70
SHA1: 77bef630aefbc659e9e91586ca436f7b5fa61be2
SHA256: 5CB16A8C5EB9F3D48FB0F3B5D0E38B6AA05BEFCCB22990C73CFDCAA33C7AC80A
File Size: 2.27 MB, 2265296 bytes
MD5: a8879907be4b3894008862b974078e12
SHA1: 8fd6a67e7f7cfc4e808f43b64c04e4a60c6ecb96
SHA256: 9376329A1115ED9D80F35CD38F85968621987068577F266E076B56FDD942F5F6
File Size: 1.67 MB, 1669000 bytes
MD5: 857dc4accb19dced61156e8c1e7ee21f
SHA1: 573b1edee8e2a8c071da50d98d58f3888bda8f5f
SHA256: 1800B741C315D709EDE844FBAF5138DB6D4F4A829CE6D75A28CFC182A413AFCF
File Size: 1.72 MB, 1721344 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
  • Opera Software
  • The Chromium Authors
  • YANDEX LLC
Company Short Name
  • Microsoft
  • The Chromium Authors
  • YANDEX LLC
File Description
  • Chromium
  • Microsoft Edge
  • Opera Internet Browser
  • Yandex
File Version
  • 96.0.4655.0
  • 92.0.902.67
  • 91.0.864.70
  • 81.0.4196.60
  • 21.11.2.538
Internal Name
  • @INTERNAL_NAME@
  • chrome_pwa_launcher
  • elevation_service_exe
  • Opera
Last Change
  • 8c35a0dac4b4b883e519423b1d775b232426761b
  • 593292d4cc4d7792034deb486ed0e3df5c7a2f4c
  • dfd15c5aad3f05175df2a43fc11b7330928d139f-refs/heads/main@{#925087}
  • eda2f229828b8182304335674621190ceba97ecd
Legal Copyright
  • Copyright (c) 2012-2021 YANDEX LLC. All Rights Reserved.
  • Copyright 2021 The Chromium Authors. All rights reserved.
  • Copyright Microsoft Corporation. All rights reserved.
  • Copyright Opera Software 2021
Official Build 1
Original Filename
  • chrome_pwa_launcher.exe
  • elevation_service.exe
Product Name
  • Chromium
  • Microsoft Edge
  • Opera Internet Browser
  • Yandex
Product Short Name
  • Chromium
  • Microsoft Edge
  • Yandex
Product Version
  • 96.0.4655.0
  • 92.0.902.67
  • 91.0.864.70
  • 81.0.4196.60
  • 21.11.2.538
Product Yandex Version 21.11.2.538

Digital Signatures

Signer Root Status
YANDEX LLC GlobalSign CodeSigning CA - G3 Self Signed
Yandex LLC GlobalSign Extended Validation CodeSigning CA - SHA256 - G3 Self Signed

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 4,241
Potentially Malicious Blocks: 149
Whitelisted Blocks: 2,764
Unknown Blocks: 1,328

Visual Map

0 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? ? 0 ? ? ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 ? x 0 0 0 ? 0 ? 0 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? 0 ? x ? ? ? ? ? 0 x ? ? 0 0 ? 0 ? 0 0 0 0 x ? 0 ? ? 0 ? ? x ? 0 ? ? 0 0 ? x 0 0 ? ? 0 ? ? ? ? x ? 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? 0 0 0 0 ? ? x ? 0 ? 0 0 x 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? ? ? 0 x 0 ? 0 ? 0 ? 0 ? ? ? 0 x ? ? x ? 0 ? 0 0 ? 0 0 ? 0 0 ? 0 ? 0 0 ? 0 ? ? 0 ? 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? 0 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? x 0 0 ? ? ? 0 0 0 ? x 0 ? ? ? ? 0 ? x 0 ? 0 ? ? 0 x x x ? 0 0 0 0 0 0 0 0 0 x ? 0 ? ? ? ? 0 ? x 0 ? 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 ? ? ? 0 0 ? 0 0 0 0 0 0 ? ? x 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 ? x ? 0 0 ? ? x 0 ? ? x 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? ? 0 0 ? ? 0 0 ? 0 0 ? ? 0 ? 0 0 ? ? ? 0 ? 0 0 ? 0 0 0 ? 0 0 ? ? 0 x ? 0 0 ? 0 ? 0 ? 0 0 x 0 ? 0 x ? 0 0 ? x ? ? x x ? 0 0 0 ? ? 0 ? 0 0 0 0 0 ? 0 0 0 ? ? 0 ? ? 0 x ? 0 ? ? 0 x ? ? ? 0 ? x ? x 0 0 ? x ? 0 0 0 ? ? 0 0 ? ? 0 0 0 x 0 ? ? 0 0 0 0 0 0 0 x 0 0 ? 0 0 ? 0 ? 0 ? 0 0 ? ? 0 ? ? ? 0 0 0 0 ? ? 0 0 0 ? ? x 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 ? ? ? ? ? 0 ? ? 0 0 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 ? 0 ? x 0 0 0 ? ? 0 0 0 ? ? ? ? 0 0 0 0 0 ? ? ? 0 0 ? ? ? 0 0 0 x ? x x ? 0 ? 0 0 ? 0 0 ? x 0 x x ? 0 ? 0 ? 0 0 0 0 x ? ? 0 0 ? ? 0 0 ? ? 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 ? ? 0 0 ? 0 ? ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? ? ? ? 0 ? 0 ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 ? ? 0 0 ? ? 0 ? ? x ? x ? 0 x ? ? ? 0 ? ? 0 0 0 ? 0 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 ? ? 0 0 ? 0 ? ? 0 0 0 0 x 0 0 0 0 0 ? ? 0 0 ? ? 0 ? ? 0 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 ? ? ? 0 0 x 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? x 0 0 0 ? ? 0 0 0 0 0 0 0 x 0 ? x 0 0 0 0 ? ? 0 ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? 0 0 ? 0 0 ? 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 ? ? ? 0 0 ? 0 ? 0 0 ? ? 0 ? ? 0 0 ? ? ? 0 0 ? 0 ? ? 0 ? 0 ? ? 0 0 ? 0 0 0 ? ? ? 0 ? ? 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 ? ? 0 0 ? ? 0 ? ? ? 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 ? x x 0 0 x x 0 0 0 ? 0 0 0 0 ? ? 0 ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 ? 0 0 ? 0 ? ? ? ? 0 ? 0 ? 0 ? 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 0 ? ? 0 0 x ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? 0 x ? ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 0 0 0 x 0 ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? x 0 0 ? 0 ? x 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 ? ? ? ? 0 0 x 0 0 0 ? ? ? 0 ? x 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 ? ? ? 0 0 x 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 ? 0 0 ? 0 x ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 0 x ? ? 0 0 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 ? ? ? 0 ? ? ? 0 0 0 0 ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? 0 0 0 ? ? 0 ? ? 0 x 0 ? 0 0 0 x 0 ? ? 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? x ? 0 0 ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? 0 0 0 ? 0 0 0 0 ? ? x 0 ? ? ? ? 0 x x ? ? 0 0 ? ? ? 0 0 ? 0 0 ? ? ? ? 0 ? ? ? 0 ? ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? ? 0 ? ? ? 0 0 0 ? 0 ? 0 ? 0 0 0 ? ? ? ? 0 ? 0 ? 0 ? 0 0 x 0 0 0 ? ? ? 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? x 0 0 0 0 ? 0 ? ? ? x ? 0 ? x ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? 0 ? 0 0 ? ? 0 0 0 ? x 0 x ? 0 ? 0 0 0 0 0 x ? 0 ? 0 ? ? 0 ? ? ? ? 0 0 ? ? 0 0 ? 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 ? 0 ? 0 x 0 0 ? 0 0 0 0 ? ? ? 0 0 0 ? ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Expiro.L

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
Show More
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Anti Debug
  • IsDebuggerPresent

Trending

Most Viewed

Loading...