Malware

Generic.Application.CoinMiner.1.B2D55EAA (file analysis)

Malware Removal

The Generic.Application.CoinMiner.1.B2D55EAA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.B2D55EAA virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Generic.Application.CoinMiner.1.B2D55EAA?


File Info:

crc32: EF593FAE
md5: 2de9354d3a5688e69466df1badcb4684
name: 2DE9354D3A5688E69466DF1BADCB4684.mlw
sha1: ddf894d4123bfeacf7cc866163013de873946fa5
sha256: 82bbc853b1a8cd98e3f9efd11052734054afde49dc4eb5bac5df3e0954bf6d71
sha512: d6fda57c7c3e68dd6452569ba1782d19781a3f26e24108faa91c13c2c7907efb556e40740753dbcf3c48a0f15a7b4efcbc481d339d71ef5c66a3eb1a88591d47
ssdeep: 24576:wRBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7:CJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Valve Corporation
ProductName: Steam
FileVersion: 2.10.91.91
FileDescription: Steam
Translation: 0x0816 0x04e4

Generic.Application.CoinMiner.1.B2D55EAA also known as:

Elasticmalicious (high confidence)
DrWebTool.BtcMine.2235
MicroWorld-eScanGeneric.Application.CoinMiner.1.B2D55EAA
FireEyeGeneric.mg.2de9354d3a5688e6
CAT-QuickHealTrojan.MinerPMF.S17010081
ALYacGeneric.Application.CoinMiner.1.B2D55EAA
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 00574bb11 )
K7GWRiskware ( 00574bb11 )
Cybereasonmalicious.d3a568
BitDefenderThetaGen:NN.ZexaCO.34700.enKfaWOUSFoi
CyrenW32/CoinMiner.YUOF-4693
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.aszwe
BitDefenderGeneric.Application.CoinMiner.1.B2D55EAA
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
TencentMalware.Win32.Gencirc.10ce19d0
Ad-AwareGeneric.Application.CoinMiner.1.B2D55EAA
SophosXMRig Miner (PUA)
ComodoApplication.Win32.CoinMiner.BS@8rlsid
F-SecureHeuristic.HEUR/AGEN.1124159
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGeneric.Application.CoinMiner.1.B2D55EAA (B)
IkarusPUA.CoinMiner
GDataWin32.Application.Coinminer.BU
JiangminRiskTool.BitMiner.calf
AviraHEUR/AGEN.1124159
Antiy-AVLTrojan/Win32.Miner
GridinsoftTrojan.Win32.CoinMiner.oa!s2
ArcabitGeneric.Application.CoinMiner.1.B2D55EAA
ZoneAlarmTrojan.Win32.Miner.aszwe
MicrosoftTrojan:Win64/CoinMiner
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R356034
Acronissuspicious
McAfeeGenericRXAA-AA!2DE9354D3A56
MAXmalware (ai score=82)
VBA32BScope.Trojan.Miner
MalwarebytesTrojan.BitCoinMiner
RisingTrojan.Miner!8.EA1 (TFE:5:1SNaNiR6GKB)
YandexTrojan.Miner!yOBUgO0rI14
SentinelOneStatic AI – Suspicious PE
FortinetW32/CryptoMiner.L!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Generic.Application.CoinMiner.1.B2D55EAA?

Generic.Application.CoinMiner.1.B2D55EAA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment