Malware

Application.BitcoinMiner.DC removal guide

Malware Removal

The Application.BitcoinMiner.DC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.BitcoinMiner.DC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Application.BitcoinMiner.DC?


File Info:

name: FBEAFD973030CF0F83D3.mlw
path: /opt/CAPEv2/storage/binaries/8fbce5417c262ea9a468e067df416080c3acd7380cdd8d791efffeafeae6a433
crc32: 899C2873
md5: fbeafd973030cf0f83d30f6c9ad5a8f5
sha1: d97d93c5247d4989f89e075f783d28dd839573d0
sha256: 8fbce5417c262ea9a468e067df416080c3acd7380cdd8d791efffeafeae6a433
sha512: dbe77e69ea234977f454f9a43df6191504bbf8d6569863ac73e9dfd79693fe2cdbe0546976a0f53093c03e51fd4e89b5d3a66fbcd27594dcc0b776e95b3fcab6
ssdeep: 24576:s2yQP4cX066khYTs/2SV8hOo2FKe0nPVPyu:spj66khqze8t6Ke0PVau
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA15014977C4B9F6C3B689B34B589B678533DB212B424E47E7D01E0A2DCB067920B2DD
sha3_384: d2e5abfba0f04924c027db1c58620a90a18fd1301a3b1690ce5ac7d7049bfbff0a4d0c6453a8d27a28a489ba5c7f4e6d
ep_bytes: 558bec6aff68504c410068801f410064
timestamp: 2010-06-27 07:06:38

Version Info:

Comments:
CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX
FileVersion: 1, 2, 0, 715
InternalName: 7zSfxNew
LegalCopyright: Copyright © 2005-2007 Oleg N. Scherbakov
LegalTrademarks:
OriginalFilename: 7zSfxNew.exe
PrivateBuild: July 14, 2007
ProductName: 7ZSfxNew
ProductVersion: 1, 2, 0, 715
SpecialBuild:
Translation: 0x0000 0x04b0

Application.BitcoinMiner.DC also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Badur.md9M
DrWebTrojan.BtcMine.244
MicroWorld-eScanApplication.BitcoinMiner.DC
FireEyeApplication.BitcoinMiner.DC
McAfeeArtemis!FBEAFD973030
CylanceUnsafe
SangforTrojan.Win32.Bitcoinminer.DG
K7AntiVirusRiskware ( 0040eff71 )
AlibabaRiskWare:Win64/Miners.43091272
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.73030c
SymantecTrojan.ADH.2
ESET-NOD32a variant of Win64/CoinMiner.J potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CKQ21
Paloaltogeneric.ml
Kasperskynot-a-virus:RiskTool.BAT.BitCoinMiner.c
BitDefenderApplication.BitcoinMiner.DC
NANO-AntivirusTrojan.Script.BtcMine.cwqvlz
AvastWin64:Malware-gen
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareApplication.BitcoinMiner.DC
SophosBitcoin Miner (PUA)
ComodoMalware@#2amy6gu7aljyx
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKQ21
McAfee-GW-EditionRDN/Generic PUP.x
EmsisoftApplication.BitcoinMiner.DC (B)
JiangminRiskTool.Generic.bn
AviraSPR/Bitcoin.AK
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.122A7AD
MicrosoftPUA:Win32/Presenoker
GridinsoftRansom.Win32.Gen.sa
ArcabitApplication.BitcoinMiner.DC
ViRobotAdware.Bitcoinminer.910376
GDataApplication.BitcoinMiner.DC
CynetMalicious (score: 99)
ALYacApplication.BitcoinMiner.DC
MalwarebytesPUP.Optional.BitCoinMiner
APEXMalicious
YandexRiskware.BitCoinMiner!+8NxibM4LI4
FortinetRiskware/BAT_BitCoinMiner
WebrootW32.Virus.BAT.BitCoinMiner
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Application.BitcoinMiner.DC?

Application.BitcoinMiner.DC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment