Threat Database Trojans Trojan.Coinminer.PB

Trojan.Coinminer.PB

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 41
First Seen: October 1, 2021
Last Seen: March 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.PB on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's resources for illicit activities, and it's essential to understand its nature and take steps to remove it to protect your data and system integrity.

What Is Trojan.Coinminer.PB?

Trojan.Coinminer.PB is a type of Trojan horse malware that is specifically designed to hijack system resources for cryptocurrency mining. Unlike viruses, Trojans do not replicate themselves but can cause significant harm by providing unauthorized access to your computer. The "Coinminer" part of its name suggests its primary function is to utilize your computer's processing power to mine cryptocurrency, which can lead to increased electricity bills, system slowdowns, and overheating issues.

How Trojan.Coinminer.PB Operates

Once installed on your system, Trojan.Coinminer.PB operates stealthily, attempting to remain undetected while it exploits your computer's resources. It may use various tactics to evade detection, including disguising itself as a legitimate program or process. The malware communicates with its command and control servers to receive updates and transmit stolen data or mined cryptocurrency. It can also download additional malicious components to further compromise your system.

Symptoms of Infection

Identifying a Trojan.Coinminer.PB infection can be challenging due to its stealthy nature, but there are several symptoms you might notice. These include significant slowdowns in system performance, increased CPU and GPU usage even when your computer is idle, unexpected crashes, and higher than usual electricity bills due to increased power consumption. You might also notice that your antivirus software is disabled or that certain security features are no longer functional.

  • Increased system slowdowns and freezes
  • High CPU and GPU usage
  • Unexpected system crashes
  • Higher electricity bills
  • Disabled security software

How to Remove Trojan.Coinminer.PB

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more straightforward removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help detect and remove the Trojan and any associated malware.
  3. Manually uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all components of the malware have been removed.

Conclusion

Removing Trojan.Coinminer.PB requires careful and immediate action to prevent further damage to your system and to protect your personal data. By understanding how this malware operates and following the steps outlined for its removal, you can restore your computer's security and performance. It's also crucial to maintain good cybersecurity practices, including keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading files from the internet.

Analysis Report

General information

Family Name: Trojan.Coinminer.PB
Signature status: No Signature

Known Samples

MD5: 7ba3ccbadc88df658dee9eb06ad3f3a7
SHA1: f935a1ca8c6e4033e2af6699fb15820b9a38e969
SHA256: C65F6B32E1416BDB57EB3B05DDB40DF93306159F004F6FCEC19C688A4481126F
File Size: 94.20 KB, 94201 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • ntdll
  • x86

Block Information

Total Blocks: 217
Potentially Malicious Blocks: 77
Whitelisted Blocks: 101
Unknown Blocks: 39

Visual Map

x 0 ? x ? x x x x 0 0 0 0 0 x x ? ? 0 x 0 0 x 0 ? 0 x 0 0 ? 0 ? ? ? ? x ? ? x 0 x x x 0 0 0 x 0 ? ? x ? ? ? x ? ? x ? x 0 x x x 0 ? x 0 x ? x 0 x ? ? 0 0 x x x ? 0 0 x 0 x x 0 x 0 x 0 0 0 0 0 0 x ? x 0 0 0 0 x 0 x x x x ? 0 ? 0 0 ? ? ? ? ? 0 0 ? x x 0 ? x 0 0 0 0 0 ? x ? 0 0 x x x 0 ? 0 0 x x 0 0 ? 0 0 x x 0 0 0 0 x 0 0 0 x 0 x 0 x 0 0 0 0 x 0 x x 0 0 x x 0 x x 0 0 0 0 x 0 x x x 0 0 x x x 0 x 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Process Shell Execute
  • WriteConsole

Shell Command Execution

WriteConsole: A c:\

Trending

Most Viewed

Loading...