Trojan

Trojan.Win32.Miner.uels (file analysis)

Malware Removal

The Trojan.Win32.Miner.uels is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.uels virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

xmr.pool.minergate.com

How to determine Trojan.Win32.Miner.uels?


File Info:

crc32: A2B6ADA5
md5: c6013fd74771235245c98272b10fd0ef
name: C6013FD74771235245C98272B10FD0EF.mlw
sha1: 4b3f12218fa2975ae08d7ba378809fb3fdb43852
sha256: 213d323707de2b3aa746240a3e66fe2758a6ce9a64e9949e6faa020dd2a8c77b
sha512: ef3602ae5ea36033b586cd8dc61786b4e80f98ea5257b71bd9aa7972db041247f29d80c568724b4085df9f3ea209f8966e454bd3bcfbcad796c96784a747bac1
ssdeep: 24576:6moO8itZ6ZidIVUp29boahPvMyDaN9cYZCC0xaWDO7W:xWZgKUp29boaxvMyDo3ZCdYWi7W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Miner.uels also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 0057b6751 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.54473
ALYacTrojan.GenericKD.40299064
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 0057b6751 )
Cybereasonmalicious.747712
CyrenW32/S-8a06ef73!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.JU potentially unwanted
APEXMalicious
AvastSFX:Agent-E [Trj]
ClamAVWin.Dropper.DarkKomet-9370806-0
KasperskyTrojan.Win32.Miner.uels
BitDefenderTrojan.GenericKD.40299064
NANO-AntivirusTrojan.Win32.Miner.fercpd
MicroWorld-eScanTrojan.GenericKD.40299064
TencentWin32.Trojan.Miner.Svqn
Ad-AwareTrojan.GenericKD.40299064
SophosTroj/Miner-QC
ComodoMalware@#22j9g6t1qobpt
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.c6013fd747712352
EmsisoftTrojan.GenericKD.40299064 (B)
MicrosoftTrojan:Win32/CoinMiner!rfn
GDataTrojan.GenericKD.40299064
McAfeePUP-HBU
MAXmalware (ai score=94)
VBA32Trojan.Miner
MalwarebytesMalware.AI.2364738755
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H06F621
IkarusPUA.CoinMiner
FortinetBAT/CoinMiner.CBBD!tr
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Miner.uels?

Trojan.Win32.Miner.uels removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment