Threat Database Trojans Trojan.Coinminer.GII

Trojan.Coinminer.GII

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 2,937
Threat Level: 80 % (High)
Infected Computers: 486
First Seen: May 20, 2024
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.GII on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system.

What Is Trojan.Coinminer.GII?

Trojan.Coinminer.GII is identified as a Trojan-type threat, which means it is a type of malware that disguises itself as legitimate software to gain unauthorized access to a computer system. The name suggests it might be involved in unauthorized cryptocurrency mining, but without specific details, it's essential to focus on general removal and security practices.

How Trojan.Coinminer.GII Operates

Trojan-type threats like Trojan.Coinminer.GII typically operate by deceiving users into installing them, often by masquerading as useful applications or attaching themselves to legitimate programs. Once installed, they can perform a variety of malicious actions, potentially including data theft, unauthorized access to system resources, and in the case of coin miners, using the system's resources to mine cryptocurrency without the user's knowledge or consent.

Symptoms of Infection

Symptoms of an infection can vary widely but may include noticeable slowdowns in system performance, increased resource usage (especially CPU and GPU), unexpected crashes, and potentially, increased electricity bills due to the system working at high capacity for extended periods. Some users might also notice unusual network activity or find unfamiliar programs installed on their system.

  • Unexplained increases in electricity bills
  • System slowdowns or crashes
  • High CPU or GPU usage
  • Unfamiliar programs or icons
  • Unusual network activity

How to Remove Trojan.Coinminer.GII

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Perform a Full Scan with a Reputable Tool: Use an anti-malware tool like SpyHunter to scan your system thoroughly. These tools are designed to detect and remove malware, including Trojans.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove anything that you don't recognize or no longer need.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, and Edge can help remove any malicious extensions or settings that the malware might have installed.
  5. Reboot and Re-scan: After taking the above steps, reboot your system and perform another scan to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.Coinminer.GII requires a methodical approach to ensure that all components of the malware are eliminated from your system. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date, using strong antivirus programs, and being cautious with emails and downloads, you can protect your system from future infections. Remember, prevention and regular system checks are key to maintaining a secure computing environment.

Analysis Report

General information

Family Name: Trojan.Coinminer.GII
Signature status: No Signature

Known Samples

MD5: da951be2792f73607099cf8dcfa783e4
SHA1: cc7fda1664b62e4fdb6d7704235badeb3f80592f
SHA256: 2030500893D7692CD7117BC14C61DFA3F832B31CA6F16D4C9F67B5D6DD9EAAF2
File Size: 4.52 MB, 4516352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Usermode Font Driver Host
File Version 10.0.19041.4355 (WinBuild.160101.0800)
Internal Name fontdrvhost.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename fontdrvhost.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.19041.4355

File Traits

  • HighEntropy
  • x64

Block Information

Total Blocks: 11,491
Potentially Malicious Blocks: 1,473
Whitelisted Blocks: 10,018
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 0 0 0 0 x x 0 x 0 x 0 x x 0 x x x x x x x x x x x 0 0 x x x x 0 0 x x x x x x x 1 1 0 0 x x x 1 1 0 1 0 0 x x x x x x 0 0 x x x x 0 0 x x x 0 x 0 x x 0 x x x x x 0 0 x 1 1 x x x 0 x x x x 0 0 x 0 x x 0 0 x x x 0 0 1 x x 0 x 0 0 x x x 1 x x x 0 x x x x x 0 0 0 x x 0 1 x x x x 1 x x x x x x x x x x x x x x x 1 x x x x x x 0 x 0 0 0 0 x x x 1 1 x 1 1 1 0 x 1 x x x 1 x 0 x x x x x 0 0 0 0 0 x 1 x x x x x x x x x x x x x x 0 0 x x 0 x x x x x x x x x x x x x x 0 x 0 x x 0 x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x 0 x x x x x x x 0 x 0 0 x 0 0 x x x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 x x x 0 x x x 0 x x x 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 0 x 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 1 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 0 0 x x x x x x x 0 x x x x x x x x x x x 0 x x 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 x 0 0 x 0 x 0 x x 0 0 0 0 0 0 x x x 0 x x 0 0 x x 0 0 0 0 0 0 x x 0 x 1 x 0 0 x 0 0 0 0 0 0 x 0 x 0 0 x x x x x 0 x x x 0 x 0 0 0 0 0 0 0 0 x 0 0 x x 0 x x x x x x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x x x x 0 x 0 x x 0 x x 0 x x x x x 0 x x x x 0 0 0 0 x 0 0 0 0 x 0 x x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 1 0 0 0 0 x x 0 x x x x x x x 0 x x x x 0 x x x 0 0 0 0 x x 1 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 x x x x x 0 0 x x x x x 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 x x x x x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 x 0 0 x x 0 x x x 0 x x 0 0 x 0 x x x x 0 x x x 0 0 0 x x x x x 0 x x x x x x 0 0 x 0 x 0 0 0 x x 0 x 0 0 x x x x x x x x x 0 x 0 x x x x x 0 x 0 x x 0 0 0 x x 0 0 x x x 0 x x x 0 x 0 x x x x x 0 0 x x x 0 0 x x x x 1 x 0 x 0 0 x 0 x x x x x x x 0 0 x 0 0 x x x x 0 x x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 x 1 1 0 0 0 0 x 0 0 0 0 x x x x x 0 0 x 0 x 0 0 x 0 x 0 0 x x x x 0 0 0 x x x 0 x x 0 0 0 0 x 0 0 0 x x 0 x x 0 x x x x x x x x 0 x x x 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 x 0 x x x 0 0 x 0 0 x 0 x 0 x 0 x x 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x 0 0 0 x 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 1 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x 0 0 0 0 x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Coinminer.GII

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Network Winsock2
  • WSAStartup
User Data Access
  • GetComputerName
  • GetUserName

Trending

Most Viewed

Loading...