Trojan

What is “Trojan.Mimdau”?

Malware Removal

The Trojan.Mimdau is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Mimdau virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Starts servers listening on 127.0.0.1:43535
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

8awang.com
tiebapic.baidu.com
imgsrc.baidu.com
www.globalsign.com

How to determine Trojan.Mimdau?


File Info:

crc32: 28F4EAD6
md5: 4b73f7724aaf6cd938d4b6243d4f7f10
name: 4B73F7724AAF6CD938D4B6243D4F7F10.mlw
sha1: 9cb2f80665b47c109c5dffc9402ee8ac0836b038
sha256: a3089e14f66f19e3d0614a5aa883e91e25000ef5f61342a05cb9cbfa861b488c
sha512: a5a1715668d07e267307b33464e3b088a2e0ec14596bf81b810c85780a26e990c29e3ae41ca0cf2d9373386bd7efc17079571d3f54efe5fa1d33310333ff9390
ssdeep: 12288:r2k2DlspiA+EyZfRzpdVxEKZNSwAFh6+FIsqNxSkJ3phY0D+aDo:rVpH+9fx3jEsNSLBwDvFDo
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (c) Microsoft Corporation. All rights reserved.
InternalName: winaudio.exe
FileVersion: 1.0.0.1
CompanyName: Microsoft Corporation
ProductName: winaudio.exe
ProductVersion: 1.0.0.1
FileDescription: winaudio.exe
OriginalFilename: winaudio.exe
Translation: 0x0409 0x04b0

Trojan.Mimdau also known as:

K7AntiVirusTrojan ( 005776e01 )
LionicTrojan.Win32.Mimdau.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader39.10333
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S20637061
ALYacGen:Variant.Graftor.962297
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2332696
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Mimdau.aefc016e
K7GWTrojan ( 005776e01 )
Cybereasonmalicious.24aaf6
CyrenW32/Agent.CHX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ULI
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Mimdau-9878619-0
KasperskyHEUR:Trojan.Win32.Mimdau.gen
BitDefenderGen:Variant.Graftor.962297
MicroWorld-eScanGen:Variant.Graftor.962297
TencentMalware.Win32.Gencirc.10ce664e
Ad-AwareGen:Variant.Graftor.962297
SophosTroj/Agent-BGQT
BitDefenderThetaGen:NN.ZexaF.34266.JmMfa0fK5Bmj
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R035C0PGN21
McAfee-GW-EditionBehavesLike.Win32.Fake.hc
FireEyeGen:Variant.Graftor.962297
EmsisoftGen:Variant.Graftor.962297 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Mimdau.bf
AviraHEUR/AGEN.1142358
Antiy-AVLTrojan/Generic.ASMalwS.34283BC
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Graftor.DEAEF9
GDataGen:Variant.Graftor.962297
AhnLab-V3Trojan/Win.Generic.R434216
McAfeeGenericRXAA-AA!4B73F7724AAF
MAXmalware (ai score=80)
VBA32Trojan.Mimdau
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R035C0PGN21
YandexTrojan.Mimdau!ooaD4jqLi4s
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.108558825.susgen
FortinetW32/Agent.ULI!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan.Mimdau?

Trojan.Mimdau removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment