Malware

About “Generic.Application.CoinMiner.1.A70733ED (B)” infection

Malware Removal

The Generic.Application.CoinMiner.1.A70733ED (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Application.CoinMiner.1.A70733ED (B) virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Generic.Application.CoinMiner.1.A70733ED (B)?


File Info:

crc32: A2CED29D
md5: c3b1c9e3ee6301dd269e9c33bf82439e
name: cpu32.exe
sha1: 21739bb636ec055aa5be001c130563a6d4bfa341
sha256: 991d15486a291122f6d3f52a8792053a38306ba78cac729fea3a13ea221537e6
sha512: a3fd3f8b61feb949ced807b4b752cae7895959912d33f80579bae7e6d1faff9e5bcd0f2039efe692c2255195a552678d4e6dadac5fa71a9a2a48b8ef126b7402
ssdeep: 24576:k8vZNZ+74xnU508TmE984HgqiczONC85P4BMPjBpne:Nd+7UU508TmE9hAqgM8NWIjBg
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1998-2015 Tencent. All Rights Reserved
InternalName: QzoneMusic
FileVersion: 9.51.3087.226
CompanyName: Tencent
Comments: QQx97f3x4e50x64adx653ex63a7x4ef63.0
ProductName: QQx97f3x4e50x64adx653ex63a7x4ef6
ProductVersion: 9.51.3087.226
FileDescription: QQx97f3x4e50x64adx653ex63a7x4ef6
OriginalFilename: QzoneMusic.EXE
Translation: 0x0804 0x04b0

Generic.Application.CoinMiner.1.A70733ED (B) also known as:

DrWebTool.BtcMine.2234
MicroWorld-eScanGeneric.Application.CoinMiner.1.A70733ED
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win32.24399
BitDefenderGeneric.Application.CoinMiner.1.A70733ED
Cybereasonmalicious.3ee630
BitDefenderThetaGen:NN.ZexaCO.33558.enKfau@4Yuli
SymantecML.Attribute.HighConfidence
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.afgqm
NANO-AntivirusRiskware.Win32.BtcMine.glouaq
AvastWin32:HarHarMiner-A [Trj]
RisingPUF.CoinMiner!8.4639 (TFE:5:MR09nqgaYWC)
Ad-AwareGeneric.Application.CoinMiner.1.A70733ED
EmsisoftGeneric.Application.CoinMiner.1.A70733ED (B)
F-SecureTrojan.TR/CoinMiner.hprel
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Spyware.tc
FireEyeGeneric.Application.CoinMiner.1.A70733ED
SophosXMRig Miner (PUA)
SentinelOneDFI – Suspicious PE
CyrenW32/Application.OJHS-0081
JiangminRiskTool.BitMiner.bznh
AviraTR/CoinMiner.hprel
FortinetW32/CryptoMiner.L!tr
Antiy-AVLTrojan/Win32.Miner
Endgamemalicious (moderate confidence)
ArcabitGeneric.Application.CoinMiner.1.A70733ED
ZoneAlarmTrojan.Win32.Miner.afgqm
MicrosoftPUA:Win32/CoinMiner
AhnLab-V3Malware/Win32.RL_Generic.R303352
Acronissuspicious
McAfeeGenericRXIW-XN!62F09C54F27A
MAXmalware (ai score=82)
VBA32BScope.Trojan.Miner
MalwarebytesTrojan.BitCoinMiner
ESET-NOD32Win32/CoinMiner.CBR
TencentMalware.Win32.Gencirc.10b0c231
YandexRiskware.Agent!
IkarusPUA.CoinMiner
GDataGeneric.Application.CoinMiner.1.A70733ED
AVGWin32:HarHarMiner-A [Trj]
PandaTrj/Genetic.gen

How to remove Generic.Application.CoinMiner.1.A70733ED (B)?

Generic.Application.CoinMiner.1.A70733ED (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment