Malware

Generic.Application.CoinMiner.1.EB291E2D malicious file

Malware Removal

The Generic.Application.CoinMiner.1.EB291E2D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.EB291E2D virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Application.CoinMiner.1.EB291E2D?


File Info:

crc32: A168F1A4
md5: b946ffa5fbef9b4d67f0c9ef48b3a08c
name: upload_file
sha1: 968f5039045edd92a9c375ac060f21412c9d7f2a
sha256: 0eb19f170372298bafdecefe726d65345213dba7008569323c1eaec838bd7fde
sha512: a8d568a5dc06c6b24da5be29a177a71863cded0fbd611c49549e56e0a086a8bc5e2fead39c6367b2f749aeb2f9012e35f5f364234f7fc3034883772d2c353838
ssdeep: 24576:TRBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7O:VJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2002 - 2017 Nir Sofer
InternalName: IECookiesView
FileVersion: 1.79
CompanyName: NirSoft
ProductName: IECookiesView
ProductVersion: 1.79
FileDescription: IECookiesView
OriginalFilename: iecv.exe
Translation: 0x0409 0x04b0

Generic.Application.CoinMiner.1.EB291E2D also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Application.CoinMiner.1.EB291E2D
FireEyeGeneric.mg.b946ffa5fbef9b4d
CAT-QuickHealPUA.CoinminerPMF.S9547169
MalwarebytesTrojan.BitCoinMiner
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGeneric.Application.CoinMiner.1.EB291E2D
K7GWAdware ( 005239ce1 )
Cybereasonmalicious.5fbef9
CyrenW32/CoinMiner.YUOF-4693
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.asyao
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
AvastWin32:Evo-gen [Susp]
Ad-AwareGeneric.Application.CoinMiner.1.EB291E2D
SophosXMRig Miner (PUA)
ComodoApplication.Win32.CoinMiner.BS@8rlsid
F-SecureHeuristic.HEUR/AGEN.1133596
DrWebTool.BtcMine.2235
ZillyaTrojan.Miner.Win32.9908
InvinceaXMRig Miner (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGeneric.Application.CoinMiner.1.EB291E2D (B)
JiangminRiskTool.BitMiner.calf
AviraHEUR/AGEN.1133596
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Miner
MicrosoftTrojan:Win64/CoinMiner
ArcabitGeneric.Application.CoinMiner.1.EB291E2D
ZoneAlarmTrojan.Win32.Miner.asyao
GDataWin32.Application.Coinminer.BU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R352663
Acronissuspicious
McAfeeGenericRXAA-AA!B946FFA5FBEF
VBA32BScope.Trojan.Miner
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
RisingTrojan.Miner!8.EA1 (TFE:5:1SNaNiR6GKB)
Ikarusnot-a-virus:PSWTool.Win32.NetPass
FortinetW32/CryptoMiner.L!tr
BitDefenderThetaGen:NN.ZexaCO.34298.dnKfaeL9Gpei
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen

How to remove Generic.Application.CoinMiner.1.EB291E2D?

Generic.Application.CoinMiner.1.EB291E2D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment