Trojan

UDS:Trojan-PSW.Win32.Mimikatz removal instruction

Malware Removal

The UDS:Trojan-PSW.Win32.Mimikatz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-PSW.Win32.Mimikatz virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine UDS:Trojan-PSW.Win32.Mimikatz?


File Info:

name: 4F8A43E2A266ED3CF1BB.mlw
path: /opt/CAPEv2/storage/binaries/7e8e1ce14eaf9c042dcf758cb9cfde7f6ea99a260201502e72d57d87d489d657
crc32: 51430419
md5: 4f8a43e2a266ed3cf1bba2429a908f76
sha1: c93c1a872656176e49385256670d6f6d530e2fdd
sha256: 7e8e1ce14eaf9c042dcf758cb9cfde7f6ea99a260201502e72d57d87d489d657
sha512: da6fde27677291bcf3d484029edf971bfef7f0f470ae579ba4d5cdc48c0e32edd48888c9a0558e984839140add30c55e3bc8b1542347bd76fecc39a527b4236b
ssdeep: 24576:Y2sdH7m3LYhVxsd8JMoFH0WO8qiYOqW+/C2OZ22qYZC/OraRVphn+dmU27njk6Um:Y22JMoFC+vYco/bt7nbUclM9OciKk
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13FB5BF29EB0B14F0D623A3B5858EEB7BDB187A158032EEBBFF4BDA0574325123C45195
sha3_384: b866b47fc441bed6a68899f145da67e0405453a1b464b1a7fb30a7867431b3ad69e771109617e68e77827660df01368a
ep_bytes: c70574d0620000000000e9a1fcffff90
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

UDS:Trojan-PSW.Win32.Mimikatz also known as:

LionicTrojan.Win32.Mimikatz.i!c
MicroWorld-eScanTrojan.GenericKD.38321322
FireEyeTrojan.GenericKD.38321322
McAfeeArtemis!4F8A43E2A266
AlibabaTrojanSpy:Win32/Mimikatz.1639d862
AvastWin32:PWSX-gen [Trj]
KasperskyUDS:Trojan-PSW.Win32.Mimikatz
BitDefenderTrojan.GenericKD.38321322
Ad-AwareTrojan.GenericKD.38321322
EmsisoftTrojan.GenericKD.38321322 (B)
ZillyaTrojan.Mimikatz.Win32.1579
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
GDataWin32.Trojan-Stealer.Mimikatz.LCVWP0
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D248BCAA
ALYacTrojan.GenericKD.38321322
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.R011H07LO21
FortinetW32/PossibleThreat
AVGWin32:PWSX-gen [Trj]

How to remove UDS:Trojan-PSW.Win32.Mimikatz?

UDS:Trojan-PSW.Win32.Mimikatz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment