Malware

Generic.Mulinex.C9D95C3D (file analysis)

Malware Removal

The Generic.Mulinex.C9D95C3D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Mulinex.C9D95C3D virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Empties the Recycle Bin, indicative of ransomware
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Mulinex.C9D95C3D?


File Info:

crc32: D6345BA0
md5: f0577a48d5f9ec267b2a3d77e56932aa
name: SQLAGENTIDC.exe
sha1: c8cfe680e6f4fa1266764845f102af2897aa8933
sha256: f273ff2db2c8e073a050ddd3c6c564f6dd67c669a30f20a83b973c44e27ae657
sha512: a0342661d08c6b9e04bb3e51098b5eb729834123ff252ceb79ad85b6fb6e955b77de54b9af36d291aebf0d4d4f05ebcd95953593fd635aa88dad180e967e4867
ssdeep: 12288:AAsjmBQyLmzkOlzPvm0Ad2X9l2QL5Lag+VcKYwU15vNO7l:AHjYmzkS7Nl245mg+owmNO7l
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2015 CHINA CITIC BANK.
InternalName: update.exe
FileVersion: 1.2.0.0720
CompanyName: x4e2dx4fe1x94f6x884c
Comments: x4e2dx4fe1x94f6x884cx7f51x94f6x4f34x4fa3
ProductName: update.exe
ProductVersion: 1.2.0.0720
FileDescription: x7f51x94f6x4f34x4fa3x5347x7ea7x7a0bx5e8f
OriginalFilename: update.exe
Translation: 0x0804 0x03a8

Generic.Mulinex.C9D95C3D also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.BtcMine.3404
MicroWorld-eScanGeneric.Mulinex.C9D95C3D
FireEyeGeneric.mg.f0577a48d5f9ec26
CAT-QuickHealPUA.BitminRI.S9338387
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00561c1b1 )
BitDefenderGeneric.Mulinex.C9D95C3D
K7GWTrojan ( 00561c1b1 )
Cybereasonmalicious.8d5f9e
ArcabitGeneric.Mulinex.C9D95C3D
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34100.HmKfaW@77Vhj
F-ProtW32/Trojan.CLL.gen!Eldorado
SymantecMiner.XMRig
APEXMalicious
ClamAVWin.Malware.Midie-7357494-0
GDataGeneric.Mulinex.C9D95C3D
KasperskyTrojan-Downloader.Win32.Bitmin.xwy
RisingBackdoor.Agent!1.B7E4 (RDMK:cmRtazrJjHMYpbCGO/JZDyHpOyxa)
Ad-AwareGeneric.Mulinex.C9D95C3D
SophosTroj/Agent-BCPO
F-SecureHeuristic.HEUR/AGEN.1046199
ZillyaTrojan.CoinMiner.Win32.25455
Trapminemalicious.high.ml.score
EmsisoftGeneric.Mulinex.C9D95C3D (B)
IkarusTrojan.Win32.CoinMiner
CyrenW32/Trojan.CLL.gen!Eldorado
JiangminTrojanDownloader.Bitmin.mz
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1046199
MAXmalware (ai score=89)
Antiy-AVLTrojan[Downloader]/Win32.Upatre
MicrosoftTrojan:Win32/Coinminer.PA!MTB
Endgamemalicious (moderate confidence)
ZoneAlarmTrojan-Downloader.Win32.Bitmin.xwy
AhnLab-V3Malware/Win32.RL_Coinminer.R328898
Acronissuspicious
VBA32BScope.Trojan.CMY3U
ALYacGeneric.Mulinex.C9D95C3D
MalwarebytesRiskWare.BitCoinMiner
ESET-NOD32a variant of Win32/CoinMiner.BUF
YandexTrojan.CoinMiner!aW1qAi1rDo4
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQWare.A!tr
WebrootW32.Malware.Gen
AVGWin32:CoinMiner-M [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Generic.Mulinex.C9D95C3D?

Generic.Mulinex.C9D95C3D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment