Threat Database Trojans Trojan.Coinminer.EDA

Trojan.Coinminer.EDA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,792
Threat Level: 80 % (High)
Infected Computers: 7
First Seen: May 17, 2026
Last Seen: July 31, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.EDA indicates that your system has been compromised by a malicious threat. This type of malware is designed to secretly use your computer's resources for cryptocurrency mining, which can lead to significant performance issues and increased electricity bills. It's essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.Coinminer.EDA?

Trojan.Coinminer.EDA is a type of Trojan horse malware that infects computers without the user's knowledge or consent. The primary purpose of this malware is to harness the computational power of infected machines to mine cryptocurrency, generating revenue for the attackers. Trojan.Coinminer.EDA can be spread through various means, including exploited vulnerabilities, phishing emails, or infected software downloads.

How Trojan.Coinminer.EDA Operates

Once installed, Trojan.Coinminer.EDA operates in the background, consuming system resources such as CPU and RAM to perform complex mathematical calculations required for cryptocurrency mining. This can lead to noticeable performance degradation, including slower system response times, increased heat generation, and reduced battery life on laptops. The malware may also communicate with its command and control servers to receive updates, transmit mined cryptocurrency, or download additional malicious components.

Symptoms of Infection

Identifying a Trojan.Coinminer.EDA infection can be challenging, as it often runs silently in the background. However, some common symptoms may indicate the presence of this malware, including:

  • Unexplained increases in system resource usage, such as high CPU or RAM utilization
  • Slow system performance, including delays or freezes
  • Overheating or increased fan activity
  • Unusual network activity or data transfers
  • Appearance of unfamiliar programs or processes in the system tray or task manager

If you've noticed any of these symptoms, it's crucial to take immediate action to remove the malware and prevent further damage.

How to Remove Trojan.Coinminer.EDA

To effectively remove Trojan.Coinminer.EDA from your system, follow these steps:

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and interfering with the removal process
  2. Perform a full scan using a reputable anti-malware tool, such as SpyHunter, to detect and remove all malicious components
  3. Uninstall any suspicious programs or applications that may be related to the infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or plugins
  5. Reboot your system and perform another full scan to ensure that all remnants of the malware have been removed

By following these steps, you can effectively remove Trojan.Coinminer.EDA and restore your system to a safe and healthy state.

Conclusion

The removal of Trojan.Coinminer.EDA requires prompt attention to prevent further damage to your system and potential financial losses due to cryptocurrency mining. By understanding the nature of this threat and following the recommended removal steps, you can protect your system and personal data from this type of malware. Remember to stay vigilant and maintain good security practices, including regular system updates, anti-malware scans, and safe browsing habits, to minimize the risk of future infections.

Analysis Report

General information

Family Name: Trojan.Coinminer.EDA
Signature status: No Signature

Known Samples

MD5: a2f3db7e04b57353bfc8a236e1074d6c
SHA1: a5f1920c8a7b90ac0f0398d4574f1e3b633b64c1
SHA256: C33F349FADFC37F147F0BC3FFA56559D621BFF095A8860111B131B1B953F3A41
File Size: 9.24 MB, 9244138 bytes
MD5: 67cca00a5f40f9b8bee42db21bf8d515
SHA1: c15fee6e2167fc2f6ac03bcdf3db062525cc2336
SHA256: F3651982F5301DB3A5FF9537DE0561262F82729DDF37C2163C44524BA50CE0A6
File Size: 9.20 MB, 9202728 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 1.00
Internal Name TJprojMain
Original Filename TJprojMain.exe
Product Name Project1
Product Version 1.00

File Traits

  • 2+ executable sections
  • HighEntropy
  • themida
  • themida section variant
  • x86

Files Modified

File Attributes
c:\program files (x86)\common files\microsoft shared\msinfo\msinfo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\3582-490\a5f1920c8a7b90ac0f0398d4574f1e3b633b64c1_0009244138 Generic Write,Read Attributes
c:\windows\svchost.com Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\classes\exefile\shell\open\command:: C:\WINDOWS\svchost.com "%1" %* RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • ShellExecute
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

open C:\Users\Kniijglt\AppData\Local\Temp\3582-490\a5f1920c8a7b90ac0f0398d4574f1e3b633b64c1_0009244138