Malware

What is “Troj/MimKatz-D”?

Malware Removal

The Troj/MimKatz-D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/MimKatz-D virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Troj/MimKatz-D?


File Info:

crc32: 691B46BE
md5: 5fda829a1d3b4f6ec1aa0811c2f98082
name: 5FDA829A1D3B4F6EC1AA0811C2F98082.mlw
sha1: 2416d965b80c5ccf5b2a422ef251a27a229a66a6
sha256: 7dfddb42746217fbde49533a00f3e72e09d2a3712e97c729a3b7aee2a172660a
sha512: 2ccf7e65405551ab93ccd99dc9a4dcaa417c1a0a5f8e9233724f9c64c5633ff0a3842ec298bb230fe8b7a3aecd1ef5805c2599aa79992a23b8b7537f0f4173a0
ssdeep: 12288:wEPr5OlYpje0ZVB7RIZngevvr3qgNVhR:w4r5rpjHD9Iaqvl
type: PE32+ executable (console) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2007 - 2019 gentilkiwi (Benjamin DELPY)
InternalName: mimikatz
FileVersion: 2.2.0.0
CompanyName: gentilkiwi (Benjamin DELPY)
PrivateBuild: Build with love for POC only
ProductName: mimikatz
SpecialBuild: :)
ProductVersion: 2.2.0.0
FileDescription: mimikatz for Windows
OriginalFilename: mimikatz.exe
Translation: 0x0409 0x04b0

Troj/MimKatz-D also known as:

K7AntiVirusHacktool ( 0043c1591 )
ALYacGen:Heur.Mimikatz.1
K7GWHacktool ( 0043c1591 )
Cybereasonmalicious.a1d3b4
SymantecHacktool.Mimikatz
ESET-NOD32a variant of Win64/Riskware.Mimikatz.D
APEXMalicious
AvastWin64:Malware-gen
ClamAVWin.Dropper.ClipBanker-9778171-0
KasperskyHEUR:Trojan-PSW.Win64.Mimikatz.gen
BitDefenderGen:Heur.Mimikatz.1
MicroWorld-eScanGen:Heur.Mimikatz.1
TencentTrojan.Win64.Mimikatz.a
Ad-AwareGen:Heur.Mimikatz.1
SophosTroj/MimKatz-D
TrendMicroHKTL_MIMIKATZ64
McAfee-GW-EditionBehavesLike.Win64.Rootkit.gc
FireEyeGeneric.mg.5fda829a1d3b4f6e
EmsisoftGen:Heur.Mimikatz.1 (B)
SentinelOneStatic AI – Malicious PE
eGambithacktool.mimikatz
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftHackTool:Win32/Mimikatz.D
GridinsoftRisk.Win64.Gen.dd!i
ZoneAlarmHEUR:Trojan-PSW.Win64.Mimikatz.gen
GDataGen:Heur.Mimikatz.1
AhnLab-V3Trojan/Win64.Mimikatz.R297820
McAfeeHTool-MimiKatz
MAXmalware (ai score=87)
MalwarebytesHackTool.Mimikatz
YandexTrojan.GenAsa!1fjvV7AuaoE
IkarusHackTool.Mimikatz
AVGWin64:Malware-gen

How to remove Troj/MimKatz-D?

Troj/MimKatz-D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment