Malware

Should I remove “Generic.Mulinex.BFE495C5”?

Malware Removal

The Generic.Mulinex.BFE495C5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Mulinex.BFE495C5 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Empties the Recycle Bin, indicative of ransomware
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Mulinex.BFE495C5?


File Info:

name: 80AC1D3A1F44E218A9E9.mlw
path: /opt/CAPEv2/storage/binaries/b456c961f8255b76c0c6d060d8680053815f49c07c0b1dacd6f2a796c9755138
crc32: BA5F4752
md5: 80ac1d3a1f44e218a9e97b0cf2cda006
sha1: 4be1ff3ff507803916711d50fdeb4b880626deb2
sha256: b456c961f8255b76c0c6d060d8680053815f49c07c0b1dacd6f2a796c9755138
sha512: 1368c6b990196992a1738aebc83ea0fefb863723efc4ca54c2819c760e7a41a0a9611813cd782e32796ac5dd5c4cfba83a9c7e648e19c1e9bd573e87614b3149
ssdeep: 12288:4+aSxLMlpJ7Qf5kikx+5FGBbozDijLhtXKHVHF9m:bhxglS5tkUMBbofi5tXKxF9m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100C41327A21C8821F61D0D31C4928E79AB3DBD459AE18E0F7538BF8C7D7039074697AE
sha3_384: 9fd1d51486406998eaf5475b4847b56b1f24cf8cd695af4cdcd008df13716acf66a5389ad8bb1e350762739477b46616
ep_bytes: 60be00604d008dbe00b0f2ff5783cdff
timestamp: 2021-11-02 12:28:06

Version Info:

CompanyName: Babylon Software Ltd.
FileDescription: Babylon Setup SE
FileVersion: 10.1.0.0
InternalName: Setup Stub
LegalCopyright: Copyright © Babylon Software Ltd. 1997-2016
OriginalFilename: SetupStub.exe
ProductName: Babylon Setup
ProductVersion: 10.1.0.0
Translation: 0x0409 0x04b0

Generic.Mulinex.BFE495C5 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.BitMiner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Mulinex.BFE495C5
FireEyeGeneric.mg.80ac1d3a1f44e218
CAT-QuickHealPUA.BitminRI.S9338387
McAfeeRDN/Generic PUP.x
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win32.40653
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.a1f44e
BaiduWin32.Trojan.Farfli.e
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.BUF
APEXMalicious
Paloaltogeneric.ml
ClamAVMultios.Coinminer.Miner-6781728-2
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
BitDefenderGeneric.Mulinex.BFE495C5
AvastWin32:CoinMiner-M [Trj]
RisingBackdoor.Agent!1.B7E4 (CLASSIC)
Ad-AwareGeneric.Mulinex.BFE495C5
EmsisoftGeneric.Mulinex.BFE495C5 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.Fakealert.59663
TrendMicroTROJ_GEN.R002C0DKQ21
McAfee-GW-EditionRDN/Generic PUP.x
SophosMal/Generic-R + Troj/Agent-BCPO
IkarusWorm.Win32.Nuj
GDataWin32.Malware.Coinminer.XYHR8O
JiangminTrojan.Sasfis.tj
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1136186
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASCommon.FA
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/CoinMiner
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.CoinMiner.R450349
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.JmMfa4zbWEgj
ALYacGeneric.Mulinex.BFE495C5
VBA32BScope.Trojan.Dynamer
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R002C0DKQ21
TencentMalware.Win32.Gencirc.10cf875c
YandexTrojan.GenAsa!CnhHeVv4fes
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
AVGWin32:CoinMiner-M [Trj]
PandaTrj/GdSda.A

How to remove Generic.Mulinex.BFE495C5?

Generic.Mulinex.BFE495C5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment