Adware

How to remove “Adware.Mikey.106145”?

Malware Removal

The Adware.Mikey.106145 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Mikey.106145 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Adware.Mikey.106145?


File Info:

name: 420306B9AE22D0912C70.mlw
path: /opt/CAPEv2/storage/binaries/2df0f0111fbb8d8f3d75f7f6057de8e41c758a7b775ce33eca4481963a8f9e46
crc32: A5E79418
md5: 420306b9ae22d0912c702f5363961165
sha1: 36fd07344462a9285487e212c0e9aba99975669a
sha256: 2df0f0111fbb8d8f3d75f7f6057de8e41c758a7b775ce33eca4481963a8f9e46
sha512: 9fc18b01901aa874513affe55b21b23526ecfbd4cae1b0661df158b4037976087e6fec9ebe8d59a2c47feb164414d96e340d9a7a5aba75353521a46192e4dc65
ssdeep: 98304:FC3hLUZWLnlG4OC0hlR/oMt7wEBxo0m+SW63p:uLRLXMt7/Bxo0m+xk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D6265B23E24188A2F128013041B727787E79B3B60EB19B53FB98CCF52F56661AF9755C
sha3_384: 544a56c1eb343eae59806de73be111bb7ea9287d4e671382a271e855a44284ba6764d28bbc279531d3047b6b4f2dbd4f
ep_bytes: 558bec6aff6870ea810068a473630064
timestamp: 2021-09-10 09:10:09

Version Info:

FileVersion: 41.1.0.1
FileDescription: www.luokexf.com
ProductName: 洛克王国旋风辅助
ProductVersion: 41.1.0.1
CompanyName: 洛克王国旋风辅助
LegalCopyright: 洛克王国旋风辅助 官网:www.luokexf.com 邮箱:admin@luokexf.com
Comments: www.luokexf.com
Translation: 0x0804 0x04b0

Adware.Mikey.106145 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lq8W
Elasticmalicious (high confidence)
FireEyeGeneric.mg.420306b9ae22d091
CAT-QuickHealTrojan.Jenix.13329
McAfeeGenericRXAA-FA!420306B9AE22
CylanceUnsafe
ZillyaAdware.Agent.Win32.170786
SangforAdware.Win32.Agent.gen
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaAdWare:Win32/FlyStudio.ade853c1
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.34182.@t0aa4frMThb
CyrenW32/Trojan.CLL.gen!Eldorado
ESET-NOD32a variant of Win32/FlyStudio.Injector.A potentially unwanted
Paloaltogeneric.ml
ClamAVWin.Trojan.Benban-9840578-0
BitDefenderGen:Variant.Adware.Mikey.106145
AvastWin32:MiscX-gen [PUP]
Ad-AwareGen:Variant.Adware.Mikey.106145
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
SophosGeneric PUA DG (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdware.Agent.aton
ArcabitTrojan.Adware.Mikey.D19EA1
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.RL_Agent.R366133
Acronissuspicious
ALYacGen:Variant.Adware.Mikey.106145
VBA32Adware.Agent
MalwarebytesTrojan.MalPack.FlyStudio
APEXMalicious
RisingTrojan.Woreflint!8.F5EA (CLOUD)
YandexPUA.Agent!IFzuylQk3vg
IkarusTrojan-Dropper.Agent
FortinetW32/CoinMiner.65CA!tr
AVGWin32:MiscX-gen [PUP]
PandaTrj/GdSda.A

How to remove Adware.Mikey.106145?

Adware.Mikey.106145 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment