Malware

What is “Generic.Application.CoinMiner.1.0BA4DFA9”?

Malware Removal

The Generic.Application.CoinMiner.1.0BA4DFA9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.0BA4DFA9 virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Application.CoinMiner.1.0BA4DFA9?


File Info:

crc32: E7F10068
md5: c3422d5c6575a0886cc5d9225fb8c9ff
name: C3422D5C6575A0886CC5D9225FB8C9FF.mlw
sha1: 0f3f550cebeb2007a5a9d13f5b4049f766410b4c
sha256: 193051da516e6773f324045009cc227dd78bb84a5c5e7db89bf2be44859c348a
sha512: 1e9bc9bd34197f91798189747524401bbdad222aacc687c4c94517a5d1867de986d6099bc9e529aa99409eff146f2b50c70ea80dc9ff3c45bc252fd8c388f265
ssdeep: 24576:CRBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7:UJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Valve Corporation
ProductName: Steam
FileVersion: 2.10.91.91
FileDescription: Steam
Translation: 0x0816 0x04e4

Generic.Application.CoinMiner.1.0BA4DFA9 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Application.CoinMiner.1.0BA4DFA9
FireEyeGeneric.mg.c3422d5c6575a088
CAT-QuickHealTrojan.MinerPMF.S17010081
McAfeeGenericRXAA-AA!C3422D5C6575
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 00574bb11 )
BitDefenderGeneric.Application.CoinMiner.1.0BA4DFA9
K7GWRiskware ( 00574bb11 )
Cybereasonmalicious.c6575a
BitDefenderThetaGen:NN.ZexaCO.34700.enKfa0qocSli
CyrenW32/CoinMiner.YUOF-4693
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.aszpv
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10ce19d0
Ad-AwareGeneric.Application.CoinMiner.1.0BA4DFA9
EmsisoftGeneric.Application.CoinMiner.1.0BA4DFA9 (B)
ComodoApplication.Win32.CoinMiner.BS@8rlsid
F-SecureHeuristic.HEUR/AGEN.1124159
DrWebTool.BtcMine.2235
ZillyaTrojan.Miner.Win32.9908
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosXMRig Miner (PUA)
IkarusPUA.CoinMiner
JiangminRiskTool.BitMiner.calf
AviraHEUR/AGEN.1124159
Antiy-AVLTrojan/Win32.Miner
MicrosoftTrojan:Win64/CoinMiner
GridinsoftTrojan.Win32.CoinMiner.oa!s2
ArcabitGeneric.Application.CoinMiner.1.0BA4DFA9
ZoneAlarmTrojan.Win32.Miner.aszpv
GDataWin32.Application.Coinminer.BU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R356034
Acronissuspicious
VBA32BScope.Trojan.Miner
MAXmalware (ai score=84)
MalwarebytesTrojan.BitCoinMiner
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
RisingTrojan.Miner!8.EA1 (TFE:5:1SNaNiR6GKB)
YandexTrojan.Miner!yOBUgO0rI14
SentinelOneStatic AI – Suspicious PE
FortinetW32/CryptoMiner.L!tr
AVGWin32:Malware-gen

How to remove Generic.Application.CoinMiner.1.0BA4DFA9?

Generic.Application.CoinMiner.1.0BA4DFA9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment