Trojan

About “Trojan:WinNT/Mediyes.A” infection

Malware Removal

The Trojan:WinNT/Mediyes.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:WinNT/Mediyes.A virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:WinNT/Mediyes.A?


File Info:

name: C7C7580993A7CB7940EF.mlw
path: /opt/CAPEv2/storage/binaries/79cfb49504a9ea4e5415ca9bb7fe21b7b665556a4ca9e8d88da8877450b09fb6
crc32: 20533B9C
md5: c7c7580993a7cb7940efcf5a58846d1e
sha1: d616ead402cd237e342201f7d9d8066d6a21e15d
sha256: 79cfb49504a9ea4e5415ca9bb7fe21b7b665556a4ca9e8d88da8877450b09fb6
sha512: 8496b51cb60c8fcb1d51fd6ded820d7962677dba2c69f196671267307daa2cc0ea0f27c0145fb04fb52f9de404b45fa35de19365af256031c40ed43ac641f332
ssdeep: 12288:MT+yZ2o9TMZpR27zPfrKCYymuT6kZcylAmhhXKA1deaXcYno4u:aDr9TMZpR27zPDKCzX6kZt3XKA1Malm
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T121C402117E47C173F19E813E88D0CBA89BBE6A1267B6E0D7F76827061C242D026743DB
sha3_384: 6f81eb37c95c5d636a3cc0e2d1c0469981d70fde53169e9b37bfae91f7adb1067b041845b5be1c198dc4d4b21ec906e3
ep_bytes: 837c2408017505e8e4300000ff742404
timestamp: 2010-04-16 07:15:45

Version Info:

FileDescription: supdate Dynamic Link Library
FileVersion: 1, 0, 0, 1
InternalName: supdate
LegalCopyright: Copyright (C) 2008
OriginalFilename: supdate.dll
ProductName: supdate Dynamic Link Library
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Trojan:WinNT/Mediyes.A also known as:

BkavW32.Common.34D9F1A0
LionicTrojan.Win32.Mediyes.5!c
DrWebTrojan.Mediyes.62
MicroWorld-eScanGen:Variant.Tedy.529673
FireEyeGeneric.mg.c7c7580993a7cb79
SkyhighBehavesLike.Win32.Generic.hc
McAfeeArtemis!C7C7580993A7
ZillyaTrojan.Generic.Win32.1047947
SangforRootkit.Win32.Mediyes.V24v
AlibabaRootkit:Win32/Mediyes.06529d6f
CrowdStrikewin/malicious_confidence_60% (W)
SymantecHacktool.Rootkit
ESET-NOD32a variant of Generik.GRNXSCL
TrendMicro-HouseCallTROJ_GEN.R002C0DB124
KasperskyRootkit.Win32.Mediyes.pel
BitDefenderGen:Variant.Tedy.529673
NANO-AntivirusTrojan.Win32.MlwGen.lialx
AvastWin32:Mediyes-H [Trj]
TencentWin32.Rootkit.Mediyes.Rqil
EmsisoftGen:Variant.Tedy.529673 (B)
F-SecureTrojan.TR/PWS.Sinowal.Gen
VIPRETrojan.GenericKD.71459804
TrendMicroTROJ_GEN.R002C0DB124
SophosMal/Generic-S
IkarusTrojan-Spy.Sinowal
MAXmalware (ai score=100)
JiangminRootkit.Mediyes.aj
GoogleDetected
AviraTR/PWS.Sinowal.Gen
Kingsoftmalware.kb.a.961
MicrosoftTrojan:WinNT/Mediyes.A
XcitiumMalware@#20bwu5kmqptra
ArcabitTrojan.Tedy.D81509
ZoneAlarmRootkit.Win32.Mediyes.pel
GDataGen:Variant.Tedy.529673
CynetMalicious (score: 99)
VBA32BScope.Trojan.Mediyes
ALYacTrojan.GenericKD.71459804
Cylanceunsafe
RisingTrojan.Mediyes!8.BCB (TFE:5:BQTp0GlVREP)
YandexTrojan.Agent!NxHNTzecqzA
FortinetW32/Dx.WDK!tr
AVGWin32:Mediyes-H [Trj]
DeepInstinctMALICIOUS
alibabacloudRootkit:Win/Mediyes.pel

How to remove Trojan:WinNT/Mediyes.A?

Trojan:WinNT/Mediyes.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment