Malware

Application.BitCoinMiner.QH information

Malware Removal

The Application.BitCoinMiner.QH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.BitCoinMiner.QH virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

Related domains:

xmr.5b6b7b.ru
www.pubyun.com

How to determine Application.BitCoinMiner.QH?


File Info:

name: 29E1C6CF1296B48D04B4.mlw
path: /opt/CAPEv2/storage/binaries/017252be35ab4320bedc85fc0306904f8e0f33df633cf6e5d6d620bffc735075
crc32: 65C78C8A
md5: 29e1c6cf1296b48d04b4dcb0f874cd11
sha1: c259abbf4c007d23d3f43919d0dde7f0e148bcc3
sha256: 017252be35ab4320bedc85fc0306904f8e0f33df633cf6e5d6d620bffc735075
sha512: 3693bb05b1ab575f21750763971770135727b6fccf29d6a8c61595f1b28c5e13b31731dbaf1a448d7f07bb48c366ee3164c095d98f93a08405539f53abf105c5
ssdeep: 12288:tyOZjINnirK65H1Ty4RNXfX0Pqo9qIOdokjS:tFZjINnirK6XNvXfX0PV9ZOS
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1D8B48D69F7640BF5D067C138C652454BE3B2788A1B61D79F13A843AA2F237D18D3EB21
sha3_384: c1cf552b12114c1c1f3c3a096aceba162c7e23f2c11a5a915b4cb16a4cdb5368586a9e7b3e6986a6642a909e6d03334a
ep_bytes: 4883ec28e8b30400004883c428e976fe
timestamp: 2017-07-17 01:58:05

Version Info:

0: [No Data]

Application.BitCoinMiner.QH also known as:

LionicRiskware.Win64.Miner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.BitCoinMiner.QH
FireEyeGeneric.mg.29e1c6cf1296b48d
McAfeeArtemis!29E1C6CF1296
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win64.243
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0050e5111 )
AlibabaTrojan:Win64/CoinMiner.d5d921e5
K7GWTrojan ( 0050e5111 )
SymantecTrojan.Coinminer.B
ESET-NOD32a variant of Win64/CoinMiner.EM
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Bitminer-9819753-0
KasperskyTrojan.Win32.Miner.aznvj
BitDefenderApplication.BitCoinMiner.QH
AvastWin32:XMRStak-A [Miner]
TencentMalware.Win32.Gencirc.10b588b6
Ad-AwareApplication.BitCoinMiner.QH
SophosXMR-Stak Miner (PUA)
DrWebTrojan.BtcMine.1559
TrendMicroPUA_COINMINE.SMALY
McAfee-GW-EditionBehavesLike.Win64.Generic.hh
EmsisoftApplication.BitCoinMiner.QH (B)
SentinelOneStatic AI – Malicious PE
GDataApplication.BitCoinMiner.QH
JiangminRiskTool.BitCoinMiner.ekw
AviraHEUR/AGEN.1133077
Antiy-AVLTrojan/Generic.ASMalwS.2135CAD
ArcabitApplication.BitCoinMiner.QH
MicrosoftTrojan:Win32/CoinMiner!bit
CynetMalicious (score: 99)
AhnLab-V3Unwanted/Win32.BitCoinMiner.R218226
Acronissuspicious
ALYacApplication.BitCoinMiner.QH
MAXmalware (ai score=73)
MalwarebytesMalware.AI.3671672174
TrendMicro-HouseCallPUA_COINMINE.SMALY
YandexTrojan.GenAsa!MEmfLnPeYoc
IkarusPUA.CoinMiner
FortinetW64/Miner.EM!tr
AVGWin32:XMRStak-A [Miner]

How to remove Application.BitCoinMiner.QH?

Application.BitCoinMiner.QH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment