Malware

About “Win32:MiniMal [Trj]” infection

Malware Removal

The Win32:MiniMal [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:MiniMal [Trj] virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32:MiniMal [Trj]?


File Info:

name: B304575839B4609EB83B.mlw
path: /opt/CAPEv2/storage/binaries/5a6f78ea16f695ea2ebdc406ececb1b22324e2bd9de1e0ff2d2efef4e2e0be57
crc32: 2BD6720E
md5: b304575839b4609eb83b1ea10f3dfcbc
sha1: ffaba10c9ef10b257fac1bd065522e35b4bc47f6
sha256: 5a6f78ea16f695ea2ebdc406ececb1b22324e2bd9de1e0ff2d2efef4e2e0be57
sha512: 83361d18ddcf77f6eb2234d3f90b9f093fd47f4e0e8134c81383e148be30ed77e38d60ec583353cdf15eff7bbfab0c9ac82ccd54b37ad72b7a283339703d7cd9
ssdeep: 48:Z1Xiz8HKR20fOO6Vrond2vyFSu8x9qZiB2nApmwGLjUxTYbCepb6s2:ZBQ3j6cInZqQwnumwC4sbC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF71B977BF0680BBC5F5267706839D5EA6B68B402742C26F12498B0994AB2CD5F2C7C1
sha3_384: c4aead315a9ed9fa2bcc3bab5839b490bb8834e4d3cdd40d269e562650ecc205ce1bea8ca00d8007abe77c857f40d763
ep_bytes: 8bec81c410ffffffe8000000005b6681
timestamp: 2014-07-07 08:12:37

Version Info:

0: [No Data]

Win32:MiniMal [Trj] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.33795
CynetMalicious (score: 100)
McAfeeGenericATG-FABE!B304575839B4
CylanceUnsafe
VIPREGen:Heur.Mint.Gubbins.19
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0049d22b1 )
K7GWTrojan-Downloader ( 0049d22b1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34592.aiW@aSETeIj
CyrenW32/Trojan.EIBJ-5084
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.F
ClamAVWin.Downloader.Upatre-9953299-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Gubbins.19
NANO-AntivirusTrojan.Win32.DownLoad3.dceouh
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
MicroWorld-eScanGen:Heur.Mint.Gubbins.19
AvastWin32:MiniMal [Trj]
RisingTrojan.Generic@AI.98 (RDMK:FCjAOaJWmLMQK1kq4XFP4w)
Ad-AwareGen:Heur.Mint.Gubbins.19
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b304575839b4609e
EmsisoftGen:Heur.Mint.Gubbins.19 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.bcqm
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3C54
MicrosoftTrojan:Win32/Upatre.MA!MTB
GDataWin32.Trojan-Downloader.Generic.8X1CZV
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R120254
VBA32TrojanSpy.Zbot
ALYacGen:Heur.Mint.Gubbins.19
MAXmalware (ai score=84)
MalwarebytesMachineLearning/Anomalous.100%
APEXMalicious
TencentTrojan-Downloader.Win32.Waski.wbq
YandexTrojan.GenAsa!+b10tL5tlnc
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Waski.C!tr
AVGWin32:MiniMal [Trj]
Cybereasonmalicious.839b46
PandaTrj/Genetic.gen

How to remove Win32:MiniMal [Trj]?

Win32:MiniMal [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment