Threat Database Trojans Trojan.Coinminer.RB

Trojan.Coinminer.RB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,151
Threat Level: 80 % (High)
Infected Computers: 4,515
First Seen: October 13, 2011
Last Seen: July 16, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.RB on your system indicates a potential security threat. This report aims to provide you with information on what this detection means, how it operates, the symptoms you might experience, and most importantly, how to remove it from your system to restore your security and privacy.

What Is Trojan.Coinminer.RB?

Trojan.Coinminer.RB is identified as a Trojan-type threat, which means it is a type of malware that disguises itself as legitimate software but actually allows unauthorized access to your computer. The name suggests it might be involved in unauthorized cryptocurrency mining, but without specific details, it's crucial to understand the general behavior of such threats. Trojans are known for their ability to spy, steal data, disrupt performance, and provide backdoors for other malware. They can be particularly dangerous because they often require user interaction to be installed, making them seem less suspicious at the time of infection.

How Trojan.Coinminer.RB Operates

Although the specifics of how Trojan.Coinminer.RB operates are not detailed here, Trojans generally work by exploiting vulnerabilities in software or human psychology to gain access to a system. Once installed, they can perform a variety of malicious functions, including but not limited to, data theft, keystroke logging, and in the case of coin miners, utilizing system resources to mine cryptocurrency without the user's knowledge or consent. They can also act as a gateway for other types of malware, making the infected system more vulnerable.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but often include noticeable system slowdowns, increased CPU usage, unexpected crashes, and changes in system settings without user intervention. In the case of coin mining malware, you might notice your system's fans working harder than usual, increased electricity bills, or general sluggishness in performance. However, some Trojans can operate silently, making them difficult to detect without proper security software.

How to Remove Trojan.Coinminer.RB

  1. Boot your computer in Safe Mode with Networking. This will limit the malware's ability to run and make it easier to remove.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure your anti-virus and anti-malware software is updated before running the scan.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time your system was infected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure the threat has been fully removed.

Conclusion

Removing Trojan.Coinminer.RB requires careful and systematic steps to ensure your system is thoroughly cleaned and protected. It's also crucial to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, being cautious with email attachments and downloads, and regularly backing up your important data. By understanding the nature of Trojan threats and taking proactive steps, you can significantly enhance your digital security and protect your personal information from falling into the wrong hands.

SpyHunter Detects & Remove Trojan.Coinminer.RB

File System Details

Trojan.Coinminer.RB may create the following file(s):
# File Name MD5 Detections
1. dat.exe dc10d8c0d3b975b7c62a8db07037bcb1 14
2. 43.exe 3401b7b3c01ea6ea4cfd13eee26369ea 3
3. E9A3.exe ea917aa918bb4f11be26ea5fb54b2daa 2
4. 9E82.exe 451dba4c8c5209afef2b83778abea472 2
5. 97C0.exe 1b01595680f25b8fb48d3c4f55df5323 2
More files

Analysis Report

General information

Family Name: Trojan.Coinminer.RB
Signature status: No Signature

Known Samples

MD5: a206c8d9ec56d8d029808e262131f40f
SHA1: cb5f348df4bae071932bb20228edaf74562c9a71
File Size: 1.43 MB, 1429196 bytes
MD5: 295ce72833826bacd60d56d1ceaeb0e3
SHA1: c11ae197eb258421c8af0537aa8336302a90ab49
SHA256: BC013FAFFE28899AD90122EF4793A3A85F5D8CA56AF7B39FC7932871BD252B3F
File Size: 3.60 MB, 3601059 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • GetConsoleWindow
  • No Version Info
  • x64

Block Information

Total Blocks: 29,529
Potentially Malicious Blocks: 245
Whitelisted Blocks: 22,682
Unknown Blocks: 6,602

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 0 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 ? ? ? x 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 ? 0 ? ? ? ? 0 ? ? ? 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 x ? 0 x ? 0 0 ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x ? 0 ? ? ? ? ? 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 ? 0 0 0 ? ? ? 0 0 0 0 0 0 ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 0 ? x ? ? ? ? 0 ? ? ? 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 ? x ? 0 ? ? ? ? ? ? 0 0 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 ? ? ? 0 ? 0 ? ? 0 ? 0 ? ? ? 0 ? 0 ? ? 0 ? 0 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? 0 0 0 ? ? 0 ? ? 0 ? 0 0 ? 0 ? ? ? ? 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? ? ? 0 ? 0 0 0 ? 0 0 0 ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? ? 0 0 0 ? ? ? x ? ? ? ? 0 ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? ? ? 0 ? 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 ? 0 ? 0 ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 ? 0 ? ? ? 0 ? ? x ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? 0 ? 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 ? ? 0 ? ? ? 0 ? ? ? 0 0 ? 0 0 0 0 0 ? ? ? 0 ? 0 ? 0 0 0 ? ? 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 0 0 0 ? 0 0 0 ? ? ? ? 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? 0 ? ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 ? ? 0 ? 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? ? 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 ? x 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? ? ? 0 0 ? ? ? 0 ? ? 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? 0 ? 0 x ? 0 ? ? 0 ? 0 0 ? ? ? ? 0 ? 0 0 ? ? 0 0 0 ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\mscli0 Synchronize,Write Attributes
c:\mscli0\2k.sys Generic Write,Read Attributes
c:\mscli0\2k.sys Synchronize,Write Attributes
c:\mscli0\32 Generic Write,Read Attributes
c:\mscli0\32 Synchronize,Write Attributes
c:\mscli0\32\mscli.exe Generic Write,Read Attributes
c:\mscli0\32\mscli.exe Synchronize,Write Attributes
c:\mscli0\64 Generic Write,Read Attributes
c:\mscli0\64 Synchronize,Write Attributes
c:\mscli0\64\mscli.exe Generic Write,Read Attributes
Show More
c:\mscli0\64\mscli.exe Synchronize,Write Attributes
c:\mscli0\__tmp_rar_sfx_access_check_20390 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\mscli0\hstart.bat Generic Write,Read Attributes
c:\mscli0\hstart.bat Synchronize,Write Attributes
c:\mscli0\hstart.vbs Generic Write,Read Attributes
c:\mscli0\hstart.vbs Synchronize,Write Attributes
c:\mscli0\lanservices.exe Generic Write,Read Attributes
c:\mscli0\lanservices.exe Synchronize,Write Attributes
c:\mscli0\mscli.dll Generic Write,Read Attributes
c:\mscli0\mscli.dll Synchronize,Write Attributes
c:\mscli0\swatch.exe Generic Write,Read Attributes
c:\mscli0\swatch.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\winrar sfx::c%%mscli0% C:/mscli0/ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applicationassociationtoasts::vbsfile_.vbs RegNtPreCreateKey
HKCU\local settings\software\microsoft\windows\shell\muicache::c:\windows\system32\wscript.exe.friendlyappname Microsoft ® Windows Based Script Host RegNtPreCreateKey
HKCU\local settings\software\microsoft\windows\shell\muicache::c:\windows\system32\wscript.exe.applicationcompany Microsoft Corporation RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 R�6 xy$kP~�ރ$������^$۴�T}��Vs}�kP~+�)����1���U���d$B HF e�/��1���h�n�}$e��$e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �J�r�i��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�������B�O�����x�%���8�5����Bx��� ���\�!IN�sb �!>!wz#@�#��#�O$kF$��$¨%:�%f RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx

Shell Command Execution

(NULL) C:\mscli0\hstart.vbs

Trending

Most Viewed

Loading...