Trojan

About “TrojanDropper:Win32/Miniduke.B” infection

Malware Removal

The TrojanDropper:Win32/Miniduke.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Miniduke.B virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine TrojanDropper:Win32/Miniduke.B?


File Info:

name: B27D362AFA345303E98C.mlw
path: /opt/CAPEv2/storage/binaries/2ba3397ee7dc7777e460d61cfe13144319207102f4efa0917d6fe6bd3f255ab9
crc32: E25E7B34
md5: b27d362afa345303e98c3f2235aa0ed5
sha1: cbf9f8e66899bf88a4415bebc44c90a673bc510c
sha256: 2ba3397ee7dc7777e460d61cfe13144319207102f4efa0917d6fe6bd3f255ab9
sha512: 3f416f90405d439ead0b7ee73338af886fa4b436c7311c10e8e42f117cce3f5d4b4f3e7ebcc48cc91aeec4731aa54f0ecbab504330a2d387512d3d5f4b316ec3
ssdeep: 24576:ce6u/p6D3RSdlc2Y4fHfxUUNb+6bWDO4MMSErTI1IvEN5E+p4eh7zATU:cOB6zY5pN532O4MniTIwSjh3wU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10EB52220B7828073C26725B44AE5F7B85779BDA22BF299CF17C556F80F242C1927731A
sha3_384: 40b533550213543d96163c0193bdec0f8f5c8f96a64097261211d1ee23405eebb8daefe3fe21b5e2d2e1f10e5f09b451
ep_bytes: e8ff200000e989feffffe8a224000085
timestamp: 2012-11-13 09:53:11

Version Info:

CompanyName: Google Inc.
FileDescription: Google Chrome Updater
FileVersion: 25.0.1364.97
InternalName: chrome_exe
LegalCopyright: Copyright 2012 Google Inc. All rights reserved.
OriginalFilename: chrome.exe
ProductName: Google Chrome Updater
ProductVersion: 25.0.1364.97
CompanyShortName: Google
ProductShortName: Chrome
LastChange: 183676
Official Build: 1
Translation: 0x0409 0x04b0

TrojanDropper:Win32/Miniduke.B also known as:

BkavW32.FamVT.FVDATTc.Worm
LionicTrojan.Win32.CosmicDuke.tnq3
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Mauvaise.SL1
MalwarebytesSpyware.PasswordStealer
ZillyaTrojan.Agent.Win32.471810
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0049b09a1 )
AlibabaTrojanDropper:Win32/Miniduke.7535324e
K7GWPassword-Stealer ( 0049b09a1 )
Cybereasonmalicious.66899b
BaiduWin32.Trojan-PSW.Agent.l
CyrenW32/Trojan.DIRN-7729
SymantecBackdoor.Tinybaron
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.CosmicDuke-3
AvastWin32:MiniDuke-G [Trj]
TencentTrojan.Win32.BitCoinMiner.la
TACHYONBackdoor/W32.CosmicDuke.2289457
ComodoTrojWare.Win32.TrojanDropper.Miniduke.DA@6l2urh
DrWebTrojan.PWS.Siggen1.28564
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R024C0CKN21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-R + Troj/CosDuke-B
IkarusTrojan-Dropper.Win32.Miniduke
GDataWin32.Trojan.PSE.10XTMWH
JiangminBackdoor/CosmicDuke.a
AviraTR/Redcap.udyxb
ViRobotTrojan.Win32.CosmicDuke.697856
MicrosoftTrojanDropper:Win32/Miniduke.B
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Agent.697856.K
Acronissuspicious
McAfeeGenericRXEN-QE!B27D362AFA34
TrendMicro-HouseCallTROJ_GEN.R024C0CKN21
RisingStealer.Agent!1.A6DB (CLASSIC)
YandexTrojan.Agent!/zyDo/9pr3w
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Ipamor.D846!tr
AVGWin32:MiniDuke-G [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureBackdoor.CosmicDuke.gen

How to remove TrojanDropper:Win32/Miniduke.B?

TrojanDropper:Win32/Miniduke.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment