Malware

Should I remove “Generic.Application.CoinMiner.1.FFAB5C92”?

Malware Removal

The Generic.Application.CoinMiner.1.FFAB5C92 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.FFAB5C92 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Application.CoinMiner.1.FFAB5C92?


File Info:

crc32: D2A7B028
md5: 3514796851d8866aaeab0a4c9fc7d6bf
name: 3514796851D8866AAEAB0A4C9FC7D6BF.mlw
sha1: 94374ac4d389def09a0c0021be6818147c2eaf04
sha256: d56c6c74d3451c1b6e20b908ab4e63b6f345671af17967a1a3815ebb04825076
sha512: 3d57a4018ec060c788d3c08ff5086069887bb516d9b4e6c226378924ed7f27fb366853e111a048b86042f432a0c3cff4562898477d14eb21ea82a63a22217128
ssdeep: 24576:2RBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7:wJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Valve Corporation
ProductName: Steam
FileVersion: 2.10.91.91
FileDescription: Steam
Translation: 0x0816 0x04e4

Generic.Application.CoinMiner.1.FFAB5C92 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Application.CoinMiner.1.FFAB5C92
FireEyeGeneric.mg.3514796851d8866a
CAT-QuickHealTrojan.MinerPMF.S17010081
McAfeeGenericRXAA-AA!3514796851D8
CylanceUnsafe
ZillyaTrojan.Miner.Win32.9908
SangforMalware
K7AntiVirusRiskware ( 00574bb11 )
K7GWRiskware ( 00574bb11 )
Cybereasonmalicious.851d88
BitDefenderThetaGen:NN.ZexaCO.34700.enKfaSumu6mi
CyrenW32/CoinMiner.YUOF-4693
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.aszwe
BitDefenderGeneric.Application.CoinMiner.1.FFAB5C92
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
RisingTrojan.Miner!8.EA1 (TFE:5:1SNaNiR6GKB)
Ad-AwareGeneric.Application.CoinMiner.1.FFAB5C92
EmsisoftGeneric.Application.CoinMiner.1.FFAB5C92 (B)
ComodoApplication.Win32.CoinMiner.BS@8rlsid
F-SecureHeuristic.HEUR/AGEN.1124159
DrWebTool.BtcMine.2235
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosXMRig Miner (PUA)
IkarusPUA.CoinMiner
GDataWin32.Application.Coinminer.BU
JiangminRiskTool.BitMiner.calf
AviraHEUR/AGEN.1124159
Antiy-AVLTrojan/Win32.Miner
GridinsoftTrojan.Win32.CoinMiner.oa!s2
ArcabitGeneric.Application.CoinMiner.1.FFAB5C92
ZoneAlarmTrojan.Win32.Miner.aszwe
MicrosoftTrojan:Win64/CoinMiner
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R356034
Acronissuspicious
MAXmalware (ai score=81)
VBA32BScope.Trojan.Miner
MalwarebytesTrojan.BitCoinMiner
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
TencentMalware.Win32.Gencirc.10ce19d0
YandexTrojan.Miner!yOBUgO0rI14
SentinelOneStatic AI – Suspicious PE
FortinetW32/CryptoMiner.L!tr
AVGWin32:Malware-gen

How to remove Generic.Application.CoinMiner.1.FFAB5C92?

Generic.Application.CoinMiner.1.FFAB5C92 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment