Malware

Mal/Generic-R + Troj/Miner-ABI removal tips

Malware Removal

The Mal/Generic-R + Troj/Miner-ABI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Miner-ABI virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Troj/Miner-ABI?


File Info:

name: 38C0FD994B54F7E1360F.mlw
path: /opt/CAPEv2/storage/binaries/5149a37647d4a5a8ef4a09ad8e545fdae60c4c0160ec8a98064b85cefb981d1c
crc32: A35E2DEF
md5: 38c0fd994b54f7e1360f976c179924f7
sha1: fd96bf6bdf35531db0b3570498c49b9b25ad5e17
sha256: 5149a37647d4a5a8ef4a09ad8e545fdae60c4c0160ec8a98064b85cefb981d1c
sha512: 92d74daeb4a54c1ffce5139b1b9335cd0b4e62dc21565ff4f0158cd76c310f45e9d9b9dfa4cc582441e710f0fa2d816fc74b1eb3c7d55daf14b224dddc7b0455
ssdeep: 96:zUd43+PhEfickgrYLdZC6XtKdabjW1C3HD9NrKYvzXmTIoDN/h18y1MWwOgzNt:ge3UYvkgkC6XtwAK1C3HfKYccbWu
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1C0F1E741BBFC8655F5FE8F326C7257500236FAA39922D75E298540195C33B848EA2FB2
sha3_384: 7096319db5ff1fe35901067632f88854630ac11ce6d52fe2073dfa1615678b0d3758c1ffbcde467e4769d3564eef5972
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-04-13 14:43:09

Version Info:

Translation: 0x0000 0x04b0
Comments: Shell Infrastructure Host
FileDescription: Shell Infrastructure Host
FileVersion: 10.0.19041.746
InternalName: extrimhack_free_gpu-watchdog.exe
LegalCopyright: © Microsoft Corporation. All Rights Reserved.
OriginalFilename: extrimhack_free_gpu-watchdog.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.746
Assembly Version: 0.0.0.0

Mal/Generic-R + Troj/Miner-ABI also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.394795
FireEyeGeneric.mg.38c0fd994b54f7e1
CAT-QuickHealTrojan.WacatacFC.S20328146
ALYacGen:Variant.Bulz.394795
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforCoinMiner.MSIL.Miner.gen
K7AntiVirusTrojan ( 0057c5581 )
AlibabaTrojan:MSIL/CoinMiner.85f56bec
K7GWTrojan ( 0057c5581 )
Cybereasonmalicious.94b54f
CyrenW64/MSIL_Coinminer.C.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/CoinMiner.BIP
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Bulz-9879448-0
KasperskyHEUR:Trojan.MSIL.Miner.gen
BitDefenderGen:Variant.Bulz.394795
AvastWin64:CoinminerX-gen [Trj]
Ad-AwareGen:Variant.Bulz.394795
SophosMal/Generic-R + Troj/Miner-ABI
DrWebTrojan.MinerNET.20
ZillyaTrojan.CoinMiner.Win32.33217
TrendMicroTROJ_GEN.R002C0DJS21
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Bulz.394795 (B)
IkarusTrojan.MSIL.CoinMiner
GDataGen:Variant.Bulz.394795
WebrootW32.Coinminer.Gen
AviraTR/CoinMiner.ttgyq
MAXmalware (ai score=82)
ArcabitTrojan.Bulz.D6062B
MicrosoftTrojan:Win64/CoinMiner.GA!MTB
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4404809
McAfeeArtemis!38C0FD994B54
VBA32Trojan.Sdum
MalwarebytesTrojan.BitCoinMiner.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0DJS21
TencentMsil.Trojan.Miner.Lmku
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetMSIL/CoinMiner.BIP!tr
AVGWin64:CoinminerX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.73691317.susgen

How to remove Mal/Generic-R + Troj/Miner-ABI?

Mal/Generic-R + Troj/Miner-ABI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment