Backdoor

Should I remove “Backdoor:Win32/Miniduke.C!dha”?

Malware Removal

The Backdoor:Win32/Miniduke.C!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Miniduke.C!dha virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Miniduke.C!dha?


File Info:

name: 8C33EF74C0674927284D.mlw
path: /opt/CAPEv2/storage/binaries/681757f4107ee38e98b9c0fb3479b9790087dedf6159035fdcbc63dfead572b6
crc32: 8C9281AC
md5: 8c33ef74c0674927284dfe98ec77aeeb
sha1: c466316ff434d2561a90d1c94ef28342f7ebc71f
sha256: 681757f4107ee38e98b9c0fb3479b9790087dedf6159035fdcbc63dfead572b6
sha512: efdd559addcb54b335966fb9f9327fc7fdf0b55ba5cbb474a1b7f33554fe4a784fe580b9e67d10e20152e4d6b392978eb2f60f32be31c2d53b7eed6eab6d0e64
ssdeep: 3072:rZ/LhS0rKgHq+rFLIwgoovufDUbZLwYIWJk9u5Se:d/LhS0rKE/FLITo9mNPIWW9g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8259E3533E4C0B1E53315B46DF1AB62967EBC384A71898B9BA41F5F2E34A918339307
sha3_384: 3e88c3f88963534d03c0fcdfad66af7be88a031ac7c64c4b40591adad9ce80660f9b15b9d035d2e29c17fef1363c5548
ep_bytes: e81c270000e989feffff578bc683e00f
timestamp: 2014-02-27 07:40:23

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Host Process for Windows Services
FileVersion: 6.1.7600.16385
InternalName: svchost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: svchost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Backdoor:Win32/Miniduke.C!dha also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.49106
FireEyeGeneric.mg.8c33ef74c0674927
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.GenericKDZ.49106
CylanceUnsafe
K7AntiVirusTrojan ( 004cf8ba1 )
K7GWTrojan ( 004cf8ba1 )
Cybereasonmalicious.4c0674
CyrenW32/Agent.XPUQ-0460
SymantecBackdoor.Tinybaron
ESET-NOD32Win32/Agent.RLQ
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Trojan.Zusy-9876296-0
KasperskyHEUR:Backdoor.Win32.CosmicDuke.gen
BitDefenderTrojan.GenericKDZ.49106
NANO-AntivirusTrojan.Win32.CosmicDuke.fiulvj
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.GenericKDZ.49106
EmsisoftTrojan.GenericKDZ.49106 (B)
ComodoBackdoor.Win32.CosmicDuke.LQ@7vpnxb
DrWebBackDoor.Miniduke.4
ZillyaBackdoor.CosmicDuke.Win32.19
McAfee-GW-EditionBehavesLike.Win32.Dropper.fz
SophosML/PE-A + Troj/CosDuke-D
JiangminBackdoor.CosmicDuke.i
AviraBDS/Miniduke.C
Antiy-AVLTrojan/Generic.ASMalwS.1E5656E
MicrosoftBackdoor:Win32/Miniduke.C!dha
GDataTrojan.GenericKDZ.49106
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R238214
McAfeeTrojan-FHFD!8C33EF74C067
MAXmalware (ai score=81)
VBA32Backdoor.CosmicDuke
MalwarebytesMalware.AI.1744403880
RisingTrojan.Generic@ML.81 (RDML:8uLapJdoCI5CGtoeLEoP+g)
YandexTrojan.GenAsa!ccJ9khjd0EY
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.41AC96
BitDefenderThetaGen:NN.ZexaF.34294.@u3@aewGcWo
AVGWin32:BackdoorX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Backdoor:Win32/Miniduke.C!dha?

Backdoor:Win32/Miniduke.C!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment