Trojan

Trojan.Win32.Miner.udec information

Malware Removal

The Trojan.Win32.Miner.udec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.udec virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

xmr.pool.minergate.com

How to determine Trojan.Win32.Miner.udec?


File Info:

crc32: 576C3985
md5: b85ffb47aa8303ea4704f4854fa2bfe8
name: B85FFB47AA8303EA4704F4854FA2BFE8.mlw
sha1: 4f28affea68fecdf09aa5c3c1efc193a1c0d426f
sha256: 1db6bb75ab5c86a42089ce4700d84afc1ac1f34f0a6f1cbedc9d7b329a773551
sha512: 800cd2b43029f1b5328912a05a4ac9ebd8d7beacac17020330b6d9cae4da74dd2b4e1898afb41567d8853ec7912fdbfb02bf3f98f0564ef15930ffd93f0784f3
ssdeep: 24576:6moO8itZ6ZidIVUp29boahPvMyDaN9cYZCC0xaWDO78:xWZgKUp29boaxvMyDo3ZCdYWi78
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Miner.udec also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 0057b6751 )
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.DownLoader26.54473
ALYacTrojan.GenericKD.40299064
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 0057b6751 )
Cybereasonmalicious.7aa830
CyrenW32/S-8a06ef73!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.JU potentially unwanted
APEXMalicious
AvastSFX:Agent-E [Trj]
ClamAVWin.Dropper.DarkKomet-9370806-0
KasperskyTrojan.Win32.Miner.udec
BitDefenderTrojan.GenericKD.40299064
NANO-AntivirusTrojan.Win32.Miner.ferdrm
MicroWorld-eScanTrojan.GenericKD.40299064
Ad-AwareTrojan.GenericKD.40299064
SophosTroj/Miner-QC
ComodoMalware@#1zzzre150yr69
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.b85ffb47aa8303ea
EmsisoftTrojan.GenericKD.40299064 (B)
MicrosoftTrojan:Win32/CoinMiner!rfn
ArcabitTrojan.Generic.D266EA38
GDataTrojan.GenericKD.40299064
McAfeePUP-HBU
MAXmalware (ai score=89)
VBA32Trojan.Miner
MalwarebytesMalware.AI.2364738755
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H06F621
IkarusPUA.CoinMiner
FortinetBAT/CoinMiner.CBBD!tr
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Miner.udec?

Trojan.Win32.Miner.udec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment