Malware

Generic.Application.CoinMiner.1.CE5B7901 (file analysis)

Malware Removal

The Generic.Application.CoinMiner.1.CE5B7901 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.CE5B7901 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Generic.Application.CoinMiner.1.CE5B7901?


File Info:

crc32: 01D29705
md5: 5553b88a762e4e2c7a1cc0d6bdf344e0
name: 5553B88A762E4E2C7A1CC0D6BDF344E0.mlw
sha1: 9964ec64282ba46ec499d50baa23aaec03f190c1
sha256: 7cffe320a7f3345257b01fb44d15940d14aed320ef59f13bc97dd42c534c6233
sha512: 4f0cb035100a1adb63421aadaa436e3108a910ecac861024d91c0a24f437e0e38d0cabd8e0f2bde68e31d758b3d9552adb46f2f809340ebd9ef630411d8ded55
ssdeep: 24576:2RBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7:wJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Valve Corporation
ProductName: Steam
FileVersion: 2.10.91.91
FileDescription: Steam
Translation: 0x0816 0x04e4

Generic.Application.CoinMiner.1.CE5B7901 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Application.CoinMiner.1.CE5B7901
FireEyeGeneric.mg.5553b88a762e4e2c
CAT-QuickHealTrojan.MinerPMF.S17010081
McAfeeGenericRXAA-AA!5553B88A762E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 00574bb11 )
BitDefenderGeneric.Application.CoinMiner.1.CE5B7901
K7GWRiskware ( 00574bb11 )
Cybereasonmalicious.a762e4
BitDefenderThetaGen:NN.ZexaCO.34700.enKfaWghW9ei
CyrenW32/CoinMiner.YUOF-4693
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.aszwe
AlibabaTrojan:Win32/Miner.3e4e35b2
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
AegisLabTrojan.Win32.Miner.4!c
RisingTrojan.Miner!8.EA1 (TFE:5:1SNaNiR6GKB)
Ad-AwareGeneric.Application.CoinMiner.1.CE5B7901
EmsisoftGeneric.Application.CoinMiner.1.CE5B7901 (B)
ComodoApplication.Win32.CoinMiner.BS@8rlsid
F-SecureHeuristic.HEUR/AGEN.1124159
DrWebTool.BtcMine.2235
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosXMRig Miner (PUA)
IkarusPUA.CoinMiner
JiangminRiskTool.BitMiner.calf
AviraHEUR/AGEN.1124159
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Miner
MicrosoftTrojan:Win64/CoinMiner
GridinsoftTrojan.Win32.CoinMiner.oa!s2
ArcabitGeneric.Application.CoinMiner.1.CE5B7901
ZoneAlarmTrojan.Win32.Miner.aszwe
GDataWin32.Application.Coinminer.BU
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Miner
ALYacGeneric.Application.CoinMiner.1.CE5B7901
MalwarebytesTrojan.BitCoinMiner
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10ce19d0
YandexTrojan.Miner!yOBUgO0rI14
SentinelOneStatic AI – Suspicious PE
FortinetW32/CryptoMiner.L!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.d58

How to remove Generic.Application.CoinMiner.1.CE5B7901?

Generic.Application.CoinMiner.1.CE5B7901 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment