Trojan

Trojan.Win32.Miner.uopw (file analysis)

Malware Removal

The Trojan.Win32.Miner.uopw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Miner.uopw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

bin.memoryson.bid
alt.zincbutter.download

How to determine Trojan.Win32.Miner.uopw?


File Info:

crc32: EEEF9FF2
md5: 235f3c82edc9e903d0b0cb149959e024
name: 235F3C82EDC9E903D0B0CB149959E024.mlw
sha1: c7acd8cd5f6d63231c09ed7b8b1b2b219e6d6ae2
sha256: 032f8ea15ed8e6698603d36ee59da6a920212941aee5b2975703c4a111b44670
sha512: dfc9618180bee7279ee7c3c755b20f92bee23d0755715bb4cdb405942c31d278859fc79b20faf71fc6ecd93d81ad354dff2ca4d442fcc2ed5e08a9c85801b7aa
ssdeep: 24576:MsKk5UR6pNeMBJSTIr7KebFbfJy6rBHAUl2xtO:MTkeR6ZDSTcuQhctF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Aonwepiiso saindehal deebahu
InternalName: ONFI.EXE
FileVersion: 3.0.3.9
CompanyName: xa9Aonwepiiso saindehal deebahu
ProductName: ONFI
ProductVersion: 3.0.3.9
OriginalFilename: onfi.exe
Translation: 0x0409 0x04e4

Trojan.Win32.Miner.uopw also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053ba2f1 )
LionicTrojan.Win32.Miner.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17914
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Miner.e692165e
K7GWTrojan ( 0053ba2f1 )
Cybereasonmalicious.2edc9e
CyrenW32/Kryptik.CVO.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Kryptik.GIVU
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Miner.uopw
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusTrojan.Win32.Kryptik.fhbjfh
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentWin32.Trojan.Miner.Hoyp
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/Generic-R + Mal/EncPk-AOA
ComodoApplication.Win32.Dlhelper.GE@8159h4
BitDefenderThetaGen:NN.ZexaF.34294.EM0@a48VRNmi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Downloader.vz
FireEyeGeneric.mg.235f3c82edc9e903
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.Generic.xhn
AviraHEUR/AGEN.1101341
Antiy-AVLTrojan/Generic.ASMalwS.27E50AD
MicrosoftProgram:Win32/Unwaders.C!rfn
GDataGen:Heur.Mint.Zamg.1
Acronissuspicious
McAfeePacked-FKC!235F3C82EDC9
MAXmalware (ai score=99)
VBA32BScope.Adware.DownloadHelper
MalwarebytesMachineLearning/Anomalous.97%
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
IkarusPUA.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GJJV!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.Win32.Miner.uopw?

Trojan.Win32.Miner.uopw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment