Malware

Generic.Application.CoinMiner.1.3800631A removal tips

Malware Removal

The Generic.Application.CoinMiner.1.3800631A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.3800631A virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Generic.Application.CoinMiner.1.3800631A?


File Info:

crc32: DF7AD3BA
md5: 0651f5a3492555f6af6822f7c57f83d0
name: upload_file
sha1: a97997f24dd44038aef5989b84fb7d0dc7f4c52e
sha256: 5b753607186f4f14661cadcc3dc84447a77cc166442cecb768eb71223927bd61
sha512: 759333ebfcd5e5e45b51045681eaaa8fd14f6d220e5a5008c5c24cc8aa39535ba6afdf903eac898054168a99db54d0e4f6250a769c6631b0e4157ab60becf4f6
ssdeep: 24576:JRBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7O:7Jzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2002 - 2017 Nir Sofer
InternalName: IECookiesView
FileVersion: 1.79
CompanyName: NirSoft
ProductName: IECookiesView
ProductVersion: 1.79
FileDescription: IECookiesView
OriginalFilename: iecv.exe
Translation: 0x0409 0x04b0

Generic.Application.CoinMiner.1.3800631A also known as:

Elasticmalicious (high confidence)
DrWebTool.BtcMine.2235
MicroWorld-eScanGeneric.Application.CoinMiner.1.3800631A
FireEyeGeneric.mg.0651f5a3492555f6
CAT-QuickHealPUA.CoinminerPMF.S9547169
McAfeeGenericRXAA-AA!0651F5A34925
CylanceUnsafe
ZillyaTrojan.Miner.Win32.9908
SangforMalware
BitDefenderGeneric.Application.CoinMiner.1.3800631A
K7GWAdware ( 005239ce1 )
Cybereasonmalicious.349255
CyrenW32/CoinMiner.YUOF-4693
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.asyao
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
Ad-AwareGeneric.Application.CoinMiner.1.3800631A
EmsisoftGeneric.Application.CoinMiner.1.3800631A (B)
F-SecureHeuristic.HEUR/AGEN.1133596
VIPRETrojan.Win32.Generic!BT
InvinceaXMRig Miner (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosXMRig Miner (PUA)
Ikarusnot-a-virus:PSWTool.Win32.NetPass
JiangminRiskTool.BitMiner.calf
AviraHEUR/AGEN.1133596
Antiy-AVLTrojan/Win32.Miner
MicrosoftTrojan:Win64/CoinMiner
ArcabitGeneric.Application.CoinMiner.1.3800631A
ZoneAlarmTrojan.Win32.Miner.asyao
GDataWin32.Application.Coinminer.BU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R352663
Acronissuspicious
VBA32BScope.Trojan.Miner
MAXmalware (ai score=84)
MalwarebytesTrojan.BitCoinMiner
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
RisingTrojan.Miner!8.EA1 (TFE:5:1SNaNiR6GKB)
FortinetW32/CryptoMiner.L!tr
AVGWin32:Evo-gen [Susp]

How to remove Generic.Application.CoinMiner.1.3800631A?

Generic.Application.CoinMiner.1.3800631A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment