Trojan

Trojan.Win32.Miner.udiw (file analysis)

Malware Removal

The Trojan.Win32.Miner.udiw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.udiw virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

xmr.pool.minergate.com

How to determine Trojan.Win32.Miner.udiw?


File Info:

crc32: 0A0FA7B0
md5: c2edd6dc152f7b85a77c8058dd77c5af
name: C2EDD6DC152F7B85A77C8058DD77C5AF.mlw
sha1: 956ba7e3d5f49b0c5acd5bdadcc7f22cac5667d5
sha256: 5fc5ad0a1ee342286ae38f5cee9fcde1523b2a90776d8ec45d44ceec5b0dddf3
sha512: bc05e436ab0d44e8742f86871eb3b4d36f95f048ce6f2f3c8df16f36cd0b21393e5cf84af2ca921e591b53b3a264818d9bfb042d3c5534d5fb0d8aeaf770a601
ssdeep: 24576:6moO8itZ6ZidIVUp29boahPvMyDaN9cYZCC0xaWDO7M:xWZgKUp29boaxvMyDo3ZCdYWi7M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Miner.udiw also known as:

K7AntiVirusAdware ( 0057b6751 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.54473
ClamAVWin.Dropper.DarkKomet-9370806-0
ALYacTrojan.GenericKD.40299064
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/CoinMiner.ali1002002
K7GWAdware ( 0057b6751 )
Cybereasonmalicious.c152f7
CyrenW32/S-8a06ef73!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.JU potentially unwanted
APEXMalicious
AvastSFX:Agent-E [Trj]
KasperskyTrojan.Win32.Miner.udiw
BitDefenderTrojan.GenericKD.40299064
NANO-AntivirusTrojan.Win32.Miner.ferevb
MicroWorld-eScanTrojan.GenericKD.40299064
TencentWin32.Trojan.Miner.Szll
Ad-AwareTrojan.GenericKD.40299064
SophosTroj/Miner-QC
ComodoMalware@#36sbmt0dz3jm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.c2edd6dc152f7b85
EmsisoftTrojan.GenericKD.40299064 (B)
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/CoinMiner!rfn
ArcabitTrojan.Generic.D266EA38
GDataTrojan.GenericKD.40299064
McAfeePUP-HBU
MAXmalware (ai score=82)
VBA32Trojan.Miner
MalwarebytesMalware.AI.2364738755
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H06F621
IkarusPUA.CoinMiner
FortinetBAT/CoinMiner.CBBD!tr
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Miner.udiw?

Trojan.Win32.Miner.udiw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment