Adware

How to remove “Adware.Midie.65942”?

Malware Removal

The Adware.Midie.65942 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Midie.65942 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Adware.Midie.65942?


File Info:

name: 037A160FA1344298F31A.mlw
path: /opt/CAPEv2/storage/binaries/a2190a7174f1fbbc0acb68d29c6a58ea959879dd2bc7554ca0e7b8f33430ede2
crc32: 8C09BCB2
md5: 037a160fa1344298f31a38305307424a
sha1: cd39b08ca101ff78a76d3e4ed4a98ade372cb079
sha256: a2190a7174f1fbbc0acb68d29c6a58ea959879dd2bc7554ca0e7b8f33430ede2
sha512: 70250fb6c47e29e6af08f57485c9e47a7eb536fa29aabb084fd5b7cb844918e122af77b071ec538e6193fa355e5b1ed8d1460f5b5f4021efac79bdffba880b07
ssdeep: 393216:dE5LSEutvawh8/PD6DdE0CnOZoVqr7ldO9m6S:dE5LSEmv3h83D6DdE0ZuARdEmh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18AD6233FB268643ED8AB173245B3936059BBB661A81F8C1E07F0051DCF668711E3FA56
sha3_384: 68ffd4d387736ef8a8c57e416cf6b8d8d439c472f4d33b0537626198fee0eab2e69b076ceb53d095400b753d95dffefa
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-05-21 05:56:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Skysoft Software
FileDescription: Skysoft MKV Converter Setup
FileVersion: 0.0.0.0
LegalCopyright:
OriginalFileName:
ProductName: Skysoft MKV Converter
ProductVersion: 0.0.0.0
Translation: 0x0000 0x04b0

Adware.Midie.65942 also known as:

LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Midie.65942
FireEyeGen:Variant.Adware.Midie.65942
ALYacGen:Variant.Adware.Midie.65942
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDropper:Win32/Ekstak.bf821703
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.agxwx
BitDefenderGen:Variant.Adware.Midie.65942
NANO-AntivirusTrojan.Win32.Ekstak.iagbdm
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Adware.Midie.65942
SophosGeneric PUA MN (PUA)
DrWebTrojan.Zadved.1654
McAfee-GW-EditionBehavesLike.Win32.BadFile.rc
EmsisoftAdware.Downloader (A)
AviraHEUR/AGEN.1144245
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Adware.Midie.65942
CynetMalicious (score: 99)
McAfeeArtemis!037A160FA134
MAXmalware (ai score=61)
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.108811177.susgen
FortinetRiskware/Application
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.fa1344

How to remove Adware.Midie.65942?

Adware.Midie.65942 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment