Malware

Generic.Application.CoinMiner.1.F4D4E8A1 (file analysis)

Malware Removal

The Generic.Application.CoinMiner.1.F4D4E8A1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.F4D4E8A1 virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Application.CoinMiner.1.F4D4E8A1?


File Info:

crc32: 0CD146A0
md5: 75028129126a98ff342ea227f0305119
name: 75028129126A98FF342EA227F0305119.mlw
sha1: db18858d926a4394cf4f5f3a034f12a697e8c4fb
sha256: 92e17758b694ce57eb9400a1fcb1f08385ac8c8ade6c08d2cf1e723cba392c87
sha512: fea048271885150cd77819b6929949f4139bd047a209337e80a9fc6b29e3d25759c9a2ef21e354de4245be71d7a54c96422c6d0aa1d0bbcfe54ea4c89abd551a
ssdeep: 24576:/RBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7:JJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Valve Corporation
ProductName: Steam
FileVersion: 2.10.91.91
FileDescription: Steam
Translation: 0x0816 0x04e4

Generic.Application.CoinMiner.1.F4D4E8A1 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Application.CoinMiner.1.F4D4E8A1
FireEyeGeneric.mg.75028129126a98ff
CAT-QuickHealTrojan.MinerPMF.S16913522
CylanceUnsafe
ZillyaTrojan.Miner.Win32.9908
SangforMalware
K7AntiVirusAdware ( 005239ce1 )
BitDefenderGeneric.Application.CoinMiner.1.F4D4E8A1
K7GWAdware ( 005239ce1 )
Cybereasonmalicious.9126a9
CyrenW32/CoinMiner.YUOF-4693
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.aszpv
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
AegisLabTrojan.Win32.Miner.4!c
Ad-AwareGeneric.Application.CoinMiner.1.F4D4E8A1
EmsisoftGeneric.Application.CoinMiner.1.F4D4E8A1 (B)
ComodoApplication.Win32.CoinMiner.BS@8rlsid
F-SecureHeuristic.HEUR/AGEN.1124159
DrWebTool.BtcMine.2235
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DLG20
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosXMRig Miner (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminRiskTool.BitMiner.calf
AviraHEUR/AGEN.1124159
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Miner
MicrosoftTrojan:Win64/CoinMiner
GridinsoftTrojan.Win32.CoinMiner.oa!s2
ArcabitGeneric.Application.CoinMiner.1.F4D4E8A1
ZoneAlarmTrojan.Win32.Miner.aszpv
GDataWin32.Application.Coinminer.BU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R356034
Acronissuspicious
McAfeeGenericRXAA-AA!75028129126A
VBA32BScope.Trojan.Miner
MalwarebytesTrojan.BitCoinMiner
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0DLG20
RisingTrojan.Miner!8.EA1 (TFE:5:1SNaNiR6GKB)
YandexTrojan.Miner!yOBUgO0rI14
IkarusPUA.CoinMiner
FortinetW32/CryptoMiner.L!tr
BitDefenderThetaGen:NN.ZexaCO.34700.enKfaC5@bZai
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.d2d

How to remove Generic.Application.CoinMiner.1.F4D4E8A1?

Generic.Application.CoinMiner.1.F4D4E8A1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment