Trojan

Trojan:Win32/MiniDuke.RDA!MTB information

Malware Removal

The Trojan:Win32/MiniDuke.RDA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/MiniDuke.RDA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/MiniDuke.RDA!MTB?


File Info:

name: E1A1C75C80B6CAB77C29.mlw
path: /opt/CAPEv2/storage/binaries/7bccf6bf29a490372e812b0517807e942f4f37108f1c03d168c8c58965a7b2f7
crc32: 8250ECB1
md5: e1a1c75c80b6cab77c294d1cbebe4453
sha1: bab7328134e0564aa22719307f063919f7fda538
sha256: 7bccf6bf29a490372e812b0517807e942f4f37108f1c03d168c8c58965a7b2f7
sha512: 8659655b0f4cbb332c1250ca054c615ed86c29f750f7e7d06990dd12549f91d9a33b433dd545ff60a5a0f6b11c10194b6b54f1fdf0da3e20cac2f9ce1f5f6bb7
ssdeep: 24576:X5216D3RSeY9BI4ETxMyUsOrcocL9iWfUMjHT14eW2SRX0FHQdrk7J:X5c6zYS6fFop9iWM6HTZnVQ1EJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CB523286285C2E3E19B0BB82DC5FD2D5372BD71F7E1435E2051DAAD0FB87A1B447A81
sha3_384: 7f3999274183a8495d11faa356579d7f6852093760782ad1a029c0902aab0a175cfba1a7fd200412baf155f151cf545f
ep_bytes: e815661a005c7ce3e2e25d0719e5e578
timestamp: 2012-11-13 09:53:11

Version Info:

CompanyName: Google Inc.
FileDescription: Google Chrome Updater
FileVersion: 25.0.1364.97
InternalName: chrome_exe
LegalCopyright: Copyright 2012 Google Inc. All rights reserved.
OriginalFilename: chrome.exe
ProductName: Google Chrome Updater
ProductVersion: 25.0.1364.97
CompanyShortName: Google
ProductShortName: Chrome
LastChange: 183676
Official Build: 1
Translation: 0x0409 0x04b0

Trojan:Win32/MiniDuke.RDA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Miniduke.4!c
MicroWorld-eScanTrojan.GenericKDZ.74286
ClamAVWin.Trojan.CosmicDuke-3
FireEyeTrojan.GenericKDZ.74286
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.GenericKDZ.74286
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.1344190
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005205011 )
AlibabaTrojan:Win32/MiniDuke.58531a38
K7GWTrojan ( 005205011 )
Cybereasonmalicious.134e05
CyrenW32/S-95d31726!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKDZ.74286
TencentPacked.Win32.Krap.wa
EmsisoftTrojan.GenericKDZ.74286 (B)
DrWebBackDoor.Miniduke.4
VIPRETrojan.GenericKDZ.74286
TrendMicroTROJ_MINIDUKE.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosTroj/Agent-AYUX
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.105ISSV
JiangminPacked.Krap.gano
Antiy-AVLTrojan[Packed]/Win32.Krap
XcitiumTrojWare.Win32.Miniduke.A@7k3fwp
ArcabitTrojan.Generic.D1222E
MicrosoftTrojan:Win32/MiniDuke.RDA!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Taranis.R233011
Acronissuspicious
McAfeeGenericRXCN-AS!E1A1C75C80B6
MAXmalware (ai score=88)
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_MINIDUKE.SM
RisingDropper.Miniduke!8.1CFA (TFE:4:itqlQcrreHC)
IkarusVirus.Win32.PeCloak
FortinetW32/GenericKDZ.7428!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/MiniDuke.RDA!MTB?

Trojan:Win32/MiniDuke.RDA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment