Malware

Generic.Application.CoinMiner.1.30CAB3A0 removal instruction

Malware Removal

The Generic.Application.CoinMiner.1.30CAB3A0 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.30CAB3A0 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Application.CoinMiner.1.30CAB3A0?


File Info:

crc32: 42411CC0
md5: f835e3f0e1afb5ffa2f5557e0f3e6729
name: cpu32.exe
sha1: a089362d5fe90bc4a00c4af007e9dd75ad6f66ba
sha256: 140963748aa8e9b6ec3100e1e5c45aab06b7db352bedd673f8e767ee4bc0be34
sha512: cf90ae3f446044d04a2decb941523cfd07e0da6b6cc0e2ac9567157b59e465d2e12b9fbb01fd03a8cdd64824f989bcf25bea2c453501dd70028d774cb8643890
ssdeep: 24576:T8vZNZ+74xnU508TmE984HgqiczONC85P4BMPjBpne:md+7UU508TmE9hAqgM8NWIjBg
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1998-2015 Tencent. All Rights Reserved
InternalName: QzoneMusic
FileVersion: 9.51.3087.226
CompanyName: Tencent
Comments: QQx97f3x4e50x64adx653ex63a7x4ef63.0
ProductName: QQx97f3x4e50x64adx653ex63a7x4ef6
ProductVersion: 9.51.3087.226
FileDescription: QQx97f3x4e50x64adx653ex63a7x4ef6
OriginalFilename: QzoneMusic.EXE
Translation: 0x0804 0x04b0

Generic.Application.CoinMiner.1.30CAB3A0 also known as:

DrWebTool.BtcMine.2234
MicroWorld-eScanGeneric.Application.CoinMiner.1.30CAB3A0
FireEyeGeneric.Application.CoinMiner.1.30CAB3A0
McAfeeGenericRXIW-XN!3E3BB1D3C87A
MalwarebytesTrojan.BitCoinMiner
VIPRETrojan.Win32.Generic!BT
BitDefenderGeneric.Application.CoinMiner.1.30CAB3A0
Cybereasonmalicious.0e1afb
BitDefenderThetaGen:NN.ZexaCO.33558.enKfa8VWbxki
SymantecML.Attribute.HighConfidence
ClamAVWin.Coinminer.Generic-7151250-0
GDataGeneric.Application.CoinMiner.1.30CAB3A0
KasperskyTrojan.Win32.Miner.afgqm
NANO-AntivirusRiskware.Win32.BtcMine.glouaq
RisingPUF.CoinMiner!8.4639 (TFE:5:MR09nqgaYWC)
Endgamemalicious (moderate confidence)
SophosXMRig Miner (PUA)
F-SecureTrojan.TR/CoinMiner.hprel
ZillyaTrojan.CoinMiner.Win32.24399
McAfee-GW-EditionBehavesLike.Win32.Spyware.tc
EmsisoftGeneric.Application.CoinMiner.1.30CAB3A0 (B)
IkarusPUA.CoinMiner
JiangminRiskTool.BitMiner.bznh
AviraTR/CoinMiner.hprel
Antiy-AVLTrojan/Win32.Miner
MicrosoftPUA:Win32/CoinMiner
ArcabitGeneric.Application.CoinMiner.1.30CAB3A0
ZoneAlarmTrojan.Win32.Miner.afgqm
AhnLab-V3Malware/Win32.RL_Generic.R303352
Acronissuspicious
VBA32BScope.Trojan.Miner
Ad-AwareGeneric.Application.CoinMiner.1.30CAB3A0
CylanceUnsafe
PandaTrj/Genetic.gen
ESET-NOD32Win32/CoinMiner.CBR
TencentMalware.Win32.Gencirc.10b0c231
YandexRiskware.Agent!
SentinelOneDFI – Suspicious PE
FortinetW32/CryptoMiner.L!tr
AVGWin32:HarHarMiner-A [Trj]
AvastWin32:HarHarMiner-A [Trj]

How to remove Generic.Application.CoinMiner.1.30CAB3A0?

Generic.Application.CoinMiner.1.30CAB3A0 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment