Threat Database Trojans Trojan.Coinminer.GCF

Trojan.Coinminer.GCF

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,454
Threat Level: 80 % (High)
Infected Computers: 3,522
First Seen: September 14, 2021
Last Seen: June 30, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.GCF on your system indicates a potential security threat that requires immediate attention. This detection name suggests a type of malicious software designed to compromise your computer's resources, possibly for cryptocurrency mining or other nefarious activities. Understanding the nature of this threat and taking prompt action to remove it is crucial to safeguard your personal data and maintain your computer's performance and security.

What Is Trojan.Coinminer.GCF?

Trojan.Coinminer.GCF is identified as a Trojan-type threat, which means it is a malicious program that can disguise itself as legitimate software. Trojans are known for their ability to grant unauthorized access to a computer, allowing hackers to steal sensitive information, install additional malware, or use the infected computer's resources for illegal activities such as cryptocurrency mining. The term "Coinminer" in the detection name implies that this particular Trojan might be involved in unauthorized cryptocurrency mining, which can significantly slow down your computer and increase your electricity bill.

How Trojan.Coinminer.GCF Operates

Malware like Trojan.Coinminer.GCF typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can run in the background, consuming system resources without the user's knowledge. It might communicate with its command and control servers to receive updates or send stolen data. The specific operations of Trojan.Coinminer.GCF can vary, but its primary goal is likely to generate revenue for its creators, either through cryptocurrency mining or other malicious means.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, some common symptoms include significant slowdowns in computer performance, increased CPU usage, overheating of the computer, and unexpected crashes or freezes. You might also notice unusual network activity or find unfamiliar programs installed on your computer. If you suspect that your computer is infected, it's essential to act quickly to minimize potential damage.

How to Remove Trojan.Coinminer.GCF

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Perform a Full Scan with a Reputable Tool: Use an anti-malware tool like SpyHunter to scan your computer thoroughly. These tools are designed to detect and remove malware, including Trojans.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or no longer need.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, or Edge can help remove any malicious extensions or settings that the Trojan might have installed.
  5. Reboot and Re-scan: After taking the above steps, reboot your computer and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Coinminer.GCF requires careful and immediate action to protect your computer and personal data. By understanding the nature of this threat and following the removal steps outlined, you can help ensure your computer's security and performance. Remember, prevention is key; keeping your operating system, software, and security tools up to date, along with being cautious when opening emails or downloading software from the internet, can significantly reduce the risk of future infections.

Analysis Report

General information

Family Name: Trojan.Coinminer.GCF
Signature status: No Signature

Known Samples

MD5: 9396da9c9e7450b9ebd099a6568f2905
SHA1: 50d589d65011e6e9cea2b41a4169dcda6f1fce25
SHA256: 71DE36A12431706932A5B08F4BD5B22C47469D3F0678909D3C1332D917381044
File Size: 153.60 KB, 153600 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description System Host
File Version 1.0.0.0
Internal Name ZCash.exe
Legal Copyright Copyright © 2017
Original Filename ZCash.exe
Product Name System Host
Product Version 1.0.0.0

File Traits

  • dll
  • x64

Block Information

Total Blocks: 61
Potentially Malicious Blocks: 0
Whitelisted Blocks: 51
Unknown Blocks: 10

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Inject.LDA
  • MSIL.Inject.LDB
  • MSIL.Krypt.TDL
  • MSIL.PSW.Agent.KL
  • MSIL.PSW.Agent.LQA
Show More
  • MSIL.PSW.Agent.TV

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 )k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�-&�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱軬洎ʫጉ嵑揊픋˹耀뫹躧隞̃鄁耀꧌ì™ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 864

Trending

Most Viewed

Loading...