Trojan

Trojan.Win32.Mimdau.pef information

Malware Removal

The Trojan.Win32.Mimdau.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Mimdau.pef virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Mimdau.pef?


File Info:

name: D541A626C8F6AB31587A.mlw
path: /opt/CAPEv2/storage/binaries/c588037fcd69f37679e1ce477e7ef44968c87416b10ba2287ad9955039a3ce12
crc32: A9F28F25
md5: d541a626c8f6ab31587a2345768e98f2
sha1: daffff9c8125d331882a9706d5cb61c5d85b95b8
sha256: c588037fcd69f37679e1ce477e7ef44968c87416b10ba2287ad9955039a3ce12
sha512: 57be2ad6ae597d315fda1ab951fb5a79f83055583058a62b5719bb9a125ec4a298fce868fddb05e903ea2cfc5a07a83aa7a80288682f5ad3232b756875ad7810
ssdeep: 12288:LuECafyEX86vD6D5a7m9MiPne/KaPt3hvynydeXa:rcoK9MivZaPtjd
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17BE49E137B809973D86709340466C3610A39FDF01BF687C39BD5226E4D367E02BBAAE5
sha3_384: 6bd314b0d719adaec0e9d0f302d71c162968272d2b658ff785adf52b02d42799e2ed9cbc227f979160a955a2c1f60a05
ep_bytes: 60be0010d2008dbe0000f5ff57eb0b90
timestamp: 2021-07-21 10:45:27

Version Info:

CompanyName: Microsoft Corporation
FileDescription: winaudio.exe
FileVersion: 1.0.0.1
InternalName: winaudio.exe
LegalCopyright: (c) Microsoft Corporation. All rights reserved.
OriginalFilename: winaudio.exe
ProductName: winaudio.exe
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

Trojan.Win32.Mimdau.pef also known as:

CynetMalicious (score: 100)
FireEyeGeneric.mg.d541a626c8f6ab31
McAfeeGenericRXAA-FA!D541A626C8F6
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.6c8f6a
CyrenW32/Mimdau.C.gen!Eldorado
Elasticmalicious (moderate confidence)
APEXMalicious
ClamAVWin.Malware.Mimdau-9888695-0
KasperskyHEUR:Trojan.Win32.Mimdau.pef
BitDefenderGen:Trojan.Heur.Pm0@!FyQOUfb
MicroWorld-eScanGen:Trojan.Heur.Pm0@!FyQOUfb
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Trojan.Heur.Pm0@!FyQOUfb
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Heur.Pm0@!FyQOUfb (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.Pm0@!FyQOUfb
JiangminTrojan.Mimdau.co
AviraTR/Redcap.aqqim
ArcabitTrojan.Heur.ED97AF
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R438019
Acronissuspicious
ALYacGen:Trojan.Heur.Pm0@!FyQOUfb
MAXmalware (ai score=88)
MalwarebytesTrojan.FakeMS
RisingBackdoor.GMProt!1.C8B6 (CLASSIC)
MaxSecureTrojan.Malware.184558169.susgen
FortinetW32/ULPM.16C0!tr
BitDefenderThetaAI:Packer.F811EB6C1C
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Mimdau.pef?

Trojan.Win32.Mimdau.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment