Trojan

Trojan.Win32.Miner.udei removal instruction

Malware Removal

The Trojan.Win32.Miner.udei is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.udei virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

xmr.pool.minergate.com

How to determine Trojan.Win32.Miner.udei?


File Info:

crc32: DE60A23F
md5: b9e770302f0c56e46ccd4b43eb0ba747
name: B9E770302F0C56E46CCD4B43EB0BA747.mlw
sha1: e081e33882a9d5dda3a4522c3b6f2a1636fd1f3d
sha256: 2668e9e8cfd92929cb248128ff5223a8c7570517f621ad779f78fad711c52121
sha512: d20089a4ce4917695c265ba639f042b8968a59e97ad14b40f8792d4d36a4abb4bf02219af15e9b314b4e8cfe4f0b0843e587efa0003f5e64b816ad64c8292848
ssdeep: 24576:6moO8itZ6ZidIVUp29boahPvMyDaN9cYZCC0xaWDO7M:xWZgKUp29boaxvMyDo3ZCdYWi7M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Miner.udei also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 0057b6751 )
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.DownLoader26.54473
ALYacTrojan.GenericKD.40299064
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 0057b6751 )
Cybereasonmalicious.02f0c5
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.JU potentially unwanted
APEXMalicious
AvastSFX:Agent-E [Trj]
ClamAVWin.Dropper.DarkKomet-9370806-0
KasperskyTrojan.Win32.Miner.udei
BitDefenderTrojan.GenericKD.40299064
NANO-AntivirusTrojan.Win32.Miner.feremd
MicroWorld-eScanTrojan.GenericKD.40299064
TencentWin32.Trojan.Miner.Pjdn
Ad-AwareTrojan.GenericKD.40299064
SophosTroj/Miner-QC
ComodoMalware@#1nu0qhbxa4p30
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.b9e770302f0c56e4
EmsisoftTrojan.GenericKD.40299064 (B)
MicrosoftTrojan:Win32/Ditertag.A
ArcabitTrojan.Generic.D266EA38
GDataTrojan.GenericKD.40299064
McAfeePUP-HBU
MAXmalware (ai score=81)
VBA32Trojan.Miner
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H06F621
IkarusPUA.CoinMiner
FortinetBAT/CoinMiner.CBBD!tr
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Miner.udei?

Trojan.Win32.Miner.udei removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment