Malware

About “Generic.Application.CoinMiner.1.54B8EC89” infection

Malware Removal

The Generic.Application.CoinMiner.1.54B8EC89 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.54B8EC89 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Application.CoinMiner.1.54B8EC89?


File Info:

crc32: 126222DC
md5: 34fe2c87a0485668f2e2ecedbf0ba938
name: 34FE2C87A0485668F2E2ECEDBF0BA938.mlw
sha1: 5aa59f97a4a5e139c5ce7d357e282b9179d603a2
sha256: a11e3602519b7a2763af42267b7ad743fee86230530890f27a9f8bd7d19602c9
sha512: 8f5d9c81dee2630f3ffb42185e251a5dd40ef6ebabba41a02f8562dfb9adecf02fbbfb804583072006cc0df78e49965e1be82cc09d65addfe9fea77fe0a98a46
ssdeep: 24576:sRBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7:GJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Valve Corporation
ProductName: Steam
FileVersion: 2.10.91.91
FileDescription: Steam
Translation: 0x0816 0x04e4

Generic.Application.CoinMiner.1.54B8EC89 also known as:

Elasticmalicious (high confidence)
DrWebTool.BtcMine.2235
MicroWorld-eScanGeneric.Application.CoinMiner.1.54B8EC89
FireEyeGeneric.mg.34fe2c87a0485668
CAT-QuickHealTrojan.MinerPMF.S17010081
McAfeeGenericRXAA-AA!34FE2C87A048
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 00574bb11 )
BitDefenderGeneric.Application.CoinMiner.1.54B8EC89
K7GWRiskware ( 00574bb11 )
Cybereasonmalicious.7a0485
BitDefenderThetaGen:NN.ZexaCO.34700.enKfamArivni
CyrenW32/CoinMiner.YUOF-4693
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.aszwe
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
TencentMalware.Win32.Gencirc.10ce19d0
Ad-AwareGeneric.Application.CoinMiner.1.54B8EC89
EmsisoftGeneric.Application.CoinMiner.1.54B8EC89 (B)
ComodoApplication.Win32.CoinMiner.BS@8rlsid
F-SecureHeuristic.HEUR/AGEN.1124159
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosXMRig Miner (PUA)
IkarusPUA.CoinMiner
JiangminRiskTool.BitMiner.calf
AviraHEUR/AGEN.1124159
Antiy-AVLTrojan/Win32.Miner
MicrosoftTrojan:Win64/CoinMiner
GridinsoftTrojan.Win32.CoinMiner.oa!s2
ArcabitGeneric.Application.CoinMiner.1.54B8EC89
ZoneAlarmTrojan.Win32.Miner.aszwe
GDataWin32.Application.Coinminer.BU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R356034
Acronissuspicious
VBA32BScope.Trojan.Miner
ALYacGeneric.Application.CoinMiner.1.54B8EC89
MAXmalware (ai score=85)
MalwarebytesTrojan.BitCoinMiner
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
RisingTrojan.Miner!8.EA1 (TFE:5:1SNaNiR6GKB)
YandexTrojan.Miner!yOBUgO0rI14
SentinelOneStatic AI – Suspicious PE
FortinetW32/CryptoMiner.L!tr
AVGWin32:Malware-gen

How to remove Generic.Application.CoinMiner.1.54B8EC89?

Generic.Application.CoinMiner.1.54B8EC89 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment