Malware

About “Generic.Application.CoinMiner.1.5ECD2CF9” infection

Malware Removal

The Generic.Application.CoinMiner.1.5ECD2CF9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.5ECD2CF9 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Application.CoinMiner.1.5ECD2CF9?


File Info:

crc32: BC1613C9
md5: 6a1cb541015caf6f1b5f2e17f078bd88
name: cpu32.exe
sha1: 73ae3303650bd4330f1cdcd4b091798601b960a5
sha256: 357d1f6d067bf0c536dd1d6a2bc520b3b7e4390a8b7ce9c8db0db3f87455a041
sha512: 37e77ddcbf7ba9873ab6843eb8d748998711a65c8241439c43caa0be9333bdee855c89c5daedfb76e84e781bd15711d68006900b8aae62b6cae3d140df2524eb
ssdeep: 24576:28vZNZ+74xnU508TmE984HgqiczONC85P4BMPjBpne:fd+7UU508TmE9hAqgM8NWIjBg
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1998-2015 Tencent. All Rights Reserved
InternalName: QzoneMusic
FileVersion: 9.51.3087.226
CompanyName: Tencent
Comments: QQx97f3x4e50x64adx653ex63a7x4ef63.0
ProductName: QQx97f3x4e50x64adx653ex63a7x4ef6
ProductVersion: 9.51.3087.226
FileDescription: QQx97f3x4e50x64adx653ex63a7x4ef6
OriginalFilename: QzoneMusic.EXE
Translation: 0x0804 0x04b0

Generic.Application.CoinMiner.1.5ECD2CF9 also known as:

MicroWorld-eScanGeneric.Application.CoinMiner.1.5ECD2CF9
FireEyeGeneric.Application.CoinMiner.1.5ECD2CF9
McAfeeGenericRXIW-XN!83B08366DF48
MalwarebytesTrojan.BitCoinMiner
ZillyaTrojan.CoinMiner.Win32.24399
BitDefenderGeneric.Application.CoinMiner.1.5ECD2CF9
Cybereasonmalicious.1015ca
BitDefenderThetaGen:NN.ZexaCO.33558.enKfaeQWajbi
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/CoinMiner.CBR
ClamAVWin.Coinminer.Generic-7151250-0
GDataGeneric.Application.CoinMiner.1.5ECD2CF9
KasperskyTrojan.Win32.Miner.afgqm
NANO-AntivirusRiskware.Win32.BtcMine.glouaq
AvastWin32:HarHarMiner-A [Trj]
RisingPUF.CoinMiner!8.4639 (TFE:5:MR09nqgaYWC)
Endgamemalicious (moderate confidence)
EmsisoftGeneric.Application.CoinMiner.1.5ECD2CF9 (B)
F-SecureTrojan.TR/CoinMiner.hprel
DrWebTool.BtcMine.2234
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Spyware.tc
SentinelOneDFI – Suspicious PE
SophosXMRig Miner (PUA)
JiangminRiskTool.BitMiner.bznh
AviraTR/CoinMiner.hprel
Antiy-AVLTrojan/Win32.Miner
MicrosoftPUA:Win32/CoinMiner
ArcabitGeneric.Application.CoinMiner.1.5ECD2CF9
AhnLab-V3Malware/Win32.RL_Generic.R303352
ZoneAlarmTrojan.Win32.Miner.afgqm
Acronissuspicious
VBA32BScope.Trojan.Miner
MAXmalware (ai score=89)
Ad-AwareGeneric.Application.CoinMiner.1.5ECD2CF9
CylanceUnsafe
TencentMalware.Win32.Gencirc.10b0c231
YandexRiskware.Agent!
IkarusPUA.CoinMiner
FortinetW32/CryptoMiner.L!tr
AVGWin32:HarHarMiner-A [Trj]
PandaTrj/Genetic.gen

How to remove Generic.Application.CoinMiner.1.5ECD2CF9?

Generic.Application.CoinMiner.1.5ECD2CF9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment