Trojan

How to remove “Trojan.Win32.Miner.uedd”?

Malware Removal

The Trojan.Win32.Miner.uedd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.uedd virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
xmr.pool.minergate.com

How to determine Trojan.Win32.Miner.uedd?


File Info:

crc32: CF41A317
md5: e9d390480d67027a62ca0347144981da
name: E9D390480D67027A62CA0347144981DA.mlw
sha1: 32371245143a7797bfbd8e3af77de1a4fa006b6e
sha256: 238a82a0fb38774c9036e07d6e4d8a874d5e7585ecceed0df20eb128c74f6ceb
sha512: 299ece688d30d8ea8ccdb2f1f447e302e8704304338dbbf419ada5b3a32dba352dde5ec50fab631c0a3a0ed7adaa573e243dbeaa05e017c147240af3b5d4e1c9
ssdeep: 24576:6moO8itZ6ZidIVUp29boahPvMyDaN9cYZCC0xaWDO7Z:xWZgKUp29boaxvMyDo3ZCdYWi7Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Miner.uedd also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 0057b6751 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.54473
ALYacTrojan.GenericKD.40299064
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 0057b6751 )
Cybereasonmalicious.80d670
CyrenW32/S-8a06ef73!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.JU potentially unwanted
APEXMalicious
AvastSFX:Agent-E [Trj]
ClamAVWin.Dropper.DarkKomet-9370806-0
KasperskyTrojan.Win32.Miner.uedd
BitDefenderTrojan.GenericKD.40299064
NANO-AntivirusTrojan.Win32.Miner.ferduy
MicroWorld-eScanTrojan.GenericKD.40299064
TencentWin32.Trojan.Miner.Anpj
Ad-AwareTrojan.GenericKD.40299064
SophosTroj/Miner-QC
ComodoMalware@#2vyygvbkcorwq
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.e9d390480d67027a
EmsisoftTrojan.GenericKD.40299064 (B)
MicrosoftTrojan:Win32/CoinMiner!rfn
ArcabitTrojan.Generic.D266EA38
GDataTrojan.GenericKD.40299064
McAfeePUP-HBU
MAXmalware (ai score=95)
VBA32Trojan.Miner
MalwarebytesMalware.AI.2364738755
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H06F621
IkarusPUA.CoinMiner
FortinetBAT/CoinMiner.CBBD!tr
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Miner.uedd?

Trojan.Win32.Miner.uedd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment