Malware

About “Generic.Application.CoinMiner.1.F639F639 (B)” infection

Malware Removal

The Generic.Application.CoinMiner.1.F639F639 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.F639F639 (B) virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Generic.Application.CoinMiner.1.F639F639 (B)?


File Info:

crc32: A0B60C0B
md5: c9332a50a96b29849af90fa058b6eea5
name: C9332A50A96B29849AF90FA058B6EEA5.mlw
sha1: 7f6f725dfca47ab16d68106690ccd81b3f5025e7
sha256: f8ad4133f1a903ac2ba0debffb2998f6dde591d2623b74fe56a8d752c5140af2
sha512: 140da0b0278ea386b1ae0867e2a6e4e45082e8a014e52fccf16cf04bc588ff56ab5a8e688d1cc34647e5c49850d89014f800fb4b8a3f6c4863d2c41487bfbf2f
ssdeep: 24576:CRBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7:UJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Valve Corporation
ProductName: Steam
FileVersion: 2.10.91.91
FileDescription: Steam
Translation: 0x0816 0x04e4

Generic.Application.CoinMiner.1.F639F639 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Application.CoinMiner.1.F639F639
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 00574bb11 )
K7GWRiskware ( 00574bb11 )
Cybereasonmalicious.0a96b2
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7151250-0
Ad-AwareGeneric.Application.CoinMiner.1.F639F639
VIPRETrojan.Win32.Generic!BT
EmsisoftGeneric.Application.CoinMiner.1.F639F639 (B)
AviraHEUR/AGEN.1124159
Antiy-AVLTrojan/Win32.Miner
GridinsoftTrojan.Win32.CoinMiner.oa!s2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R356034
Acronissuspicious
MalwarebytesTrojan.BitCoinMiner
TencentMalware.Win32.Gencirc.10ce19d0
SentinelOneStatic AI – Suspicious PE
FortinetW32/CryptoMiner.L!tr

How to remove Generic.Application.CoinMiner.1.F639F639 (B)?

Generic.Application.CoinMiner.1.F639F639 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment