Trojan

Trojan.Win32.Miner.uens removal

Malware Removal

The Trojan.Win32.Miner.uens is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.uens virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

xmr.pool.minergate.com

How to determine Trojan.Win32.Miner.uens?


File Info:

crc32: 84B8014E
md5: 5be3f1c8f6a1f3f5eb71fe8ed84eaaa3
name: 5BE3F1C8F6A1F3F5EB71FE8ED84EAAA3.mlw
sha1: c4b53900156ca9d3f435816228b51bd8140803de
sha256: 1e3d75d26702a645eb1fff9754796c5d1dbbc960ff8cb099e2293a9d14649164
sha512: a4f26027a269e87eebe8359321a077aacab7e4b346d16094b3cd1d95a2ec79eea64c79fb2fc6c685f44a79385f4a759efd43b50273183655d8d34251b294fd63
ssdeep: 24576:6moO8itZ6ZidIVUp29boahPvMyDaN9cYZCC0xaWDO7X:xWZgKUp29boaxvMyDo3ZCdYWi7X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Miner.uens also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 0057b6751 )
DrWebTrojan.DownLoader26.54473
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.40299064
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/CoinMiner.ali1002002
K7GWAdware ( 0057b6751 )
Cybereasonmalicious.8f6a1f
CyrenW32/S-8a06ef73!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.JU potentially unwanted
APEXMalicious
AvastSFX:Agent-E [Trj]
ClamAVWin.Dropper.DarkKomet-9370806-0
KasperskyTrojan.Win32.Miner.uens
BitDefenderTrojan.GenericKD.40299064
NANO-AntivirusTrojan.Win32.CoinMiner.feqnev
MicroWorld-eScanTrojan.GenericKD.40299064
TencentWin32.Trojan.Miner.Tafj
Ad-AwareTrojan.GenericKD.40299064
SophosMal/Generic-S + Troj/Miner-QC
ComodoMalware@#mapppmatzpb5
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.5be3f1c8f6a1f3f5
EmsisoftTrojan.GenericKD.40299064 (B)
MicrosoftTrojan:Win32/CoinMiner.AC!rfn
GDataTrojan.GenericKD.40299064
McAfeePUP-HBU
MAXmalware (ai score=100)
VBA32Trojan.Miner
MalwarebytesMalware.AI.2364738755
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H06F621
IkarusPUA.CoinMiner
FortinetBAT/CoinMiner.CBBD!tr
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Miner.uens?

Trojan.Win32.Miner.uens removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment