Malware

Application.BitCoinMiner.LX removal tips

Malware Removal

The Application.BitCoinMiner.LX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.BitCoinMiner.LX virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Installs OpenCL library, probably to mine Bitcoins
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by registry key
  • Collects information to fingerprint the system

How to determine Application.BitCoinMiner.LX?


File Info:

name: CED7301FC67336EC8B01.mlw
path: /opt/CAPEv2/storage/binaries/15a908e6c18f30309d550fda268beaa4cc8c22af1c26db4c5415690259e6e6e4
crc32: 85D172A1
md5: ced7301fc67336ec8b01cacd525d13b7
sha1: dd893682709695db0c40a465b22b0929d73a30c3
sha256: 15a908e6c18f30309d550fda268beaa4cc8c22af1c26db4c5415690259e6e6e4
sha512: a3783e6695ba4d0ddd585e605c06757d3095e19715b7605663474212e528d74217976266bbb83d6ab4a05d43dda401b68a2aa6f54278b54525df9d49a012e817
ssdeep: 49152:BjWbJ173Z/V56rq8mvTnMkXFb4xtfYj95:I3Z6rq8qTnM4p4fq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11275333C21D55107ECF52DB3DA7B97B2D1AE6278C292C69B07F0F6584C26287C68931B
sha3_384: 27a7d6fdf20550c7798a6e7d3e56debe1f3f8ac54a9a724a41592c83ed9733abc63cba0dc7c0017c86d857cefde51b28
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2015-08-05 00:47:29

Version Info:

Comments:
CompanyName: Open Source
FileDescription: GPLYRA - Setup
FileVersion: 5.2.5
InternalName: GPLYRA
LegalCopyright: 2015 - Open Source
LegalTrademarks:
OriginalFilename: -
ProductName: GPLYRA - Setup
ProductVersion: 5.2.5
Translation: 0x0409 0x04e4

Application.BitCoinMiner.LX also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.Generic.1!c
DrWebTrojan.BtcMine.1013
MicroWorld-eScanApplication.BitCoinMiner.LX
FireEyeApplication.BitCoinMiner.LX
ALYacApplication.BitCoinMiner.LX
MalwarebytesPUP.Optional.BitCoinMiner
ZillyaTrojan.Miner.Win32.15083
K7AntiVirusTrojan ( 00568ceb1 )
AlibabaTrojan:Win32/Miners.c16e7c8d
K7GWTrojan ( 00568ceb1 )
Cybereasonmalicious.fc6733
SymantecMiner.Bitcoinminer
ESET-NOD32a variant of Win32/CoinMiner.BY potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PKS21
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7150979-0
KasperskyHEUR:Trojan.Win32.Miner.gen
BitDefenderApplication.BitCoinMiner.LX
NANO-AntivirusTrojan.Script.BtcMine.eialfa
Ad-AwareApplication.BitCoinMiner.LX
SophosGeneric Reputation PUA (PUA)
ComodoApplicUnwnt@#22pw94yk7sfqz
VIPRERiskTool.Win32.BitCoinMiner (not malicious)
TrendMicroTROJ_GEN.R002C0PKS21
McAfee-GW-EditionBehavesLike.Win32.Addrop.tc
EmsisoftApplication.BitCoinMiner.LX (B)
AviraHEUR/AGEN.1136246
Antiy-AVLTrojan/Generic.ASMalwNS.3B1
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Gen.sa
ViRobotTrojan.Win32.Z.Miner.1681097
GDataApplication.BitCoinMiner.LX
CynetMalicious (score: 99)
McAfeeArtemis!CED7301FC673
MAXmalware (ai score=100)
VBA32Trojan.Miner
CylanceUnsafe
PandaTrj/CI.A
APEXMalicious
RisingHackTool.CoinMiner!1.CA68 (CLASSIC)
YandexTrojan.GenAsa!tZUU636rMBs
SentinelOneStatic AI – Malicious PE
FortinetNSIS/CoinMiner.A!tr
WebrootPua.Miner
AVGNSIS:CoinMiner-A [Drp]
AvastNSIS:CoinMiner-A [Drp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Application.BitCoinMiner.LX?

Application.BitCoinMiner.LX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment