Adware

Adware.Mikey.49900 removal tips

Malware Removal

The Adware.Mikey.49900 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Mikey.49900 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Adware.Mikey.49900?


File Info:

name: 00AD7DF14BEF7F3816AC.mlw
path: /opt/CAPEv2/storage/binaries/3f86c064d788e36f98a23618cdb5a813e5113095fc6fbe61f8349758c1dc7808
crc32: F3782444
md5: 00ad7df14bef7f3816ac5a55008ad562
sha1: d290a6ffd07d311f39813d1717b878a5c84e8774
sha256: 3f86c064d788e36f98a23618cdb5a813e5113095fc6fbe61f8349758c1dc7808
sha512: d6d19877f068f8ed398410244429724ddb3825be534e94a0674f0417a453ad8ce1b2714d33f9dd1054d2048854ca30d9960c18bce3c577976288b1eb6c458524
ssdeep: 24576:pLYX34X/q35XPWdWArhwMR/ZCcZbpW0K33ATHvSL/M1906V9Q1ZpOmizpRcKs/VZ:pLYX3E/q35XPWdWArhwMR/ZCcZbpWDM+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118459D318513BE7AF66E3979C00C2D911C687E93431886D7EB88A97A768C581DF3C4BD
sha3_384: eac877b212bdcf997c3e2a1fcbc7fcbc00de08b431a00e4924b2eaea5caeeaa6c37d02eedebad46a34252919ba95fc8d
ep_bytes: e8f0450000e979feffffcccccccccccc
timestamp: 2016-10-20 09:57:20

Version Info:

CompanyName: 3UI3ciptets.Inc
FileDescription: h5hkf5o6Onp7K
FileVersion: 10.4.155.5113
ProductVersion: 19.73.134.1307
InternalName: r50raC
OriginalFilename: r50raC.exe
ProductName: rAvSF6VtgLN software
LegalCopyright: W9K1ONxorlhpi (c) 2016
LegalTrademarks: 7sl1aPmi5a1SF registered trademark
Comments: cEeM5n1vS3XE3Kax is a part of an open office
Translation: 0x0409 0x04e4

Adware.Mikey.49900 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Mikey.49900
FireEyeGeneric.mg.00ad7df14bef7f38
CAT-QuickHealDownloader.Kasinst.B5
McAfeeGenericRXGH-GH!00AD7DF14BEF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforPUP.Win32.Graftor.364197
K7AntiVirusAdware ( 004f769a1 )
K7GWAdware ( 004f769a1 )
CrowdStrikewin/malicious_confidence_60% (D)
BaiduWin32.Adware.Agent.e
CyrenW32/S-0abd1054!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Instally.K potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:Downloader.Win32.Kasinst.aam
BitDefenderGen:Variant.Adware.Mikey.49900
NANO-AntivirusRiskware.Win32.Adw.egaqod
AvastFileRepMalware
TencentMalware.Win32.Gencirc.10b1342a
Ad-AwareGen:Variant.Adware.Mikey.49900
EmsisoftGen:Variant.Adware.Mikey.49900 (B)
ComodoApplication.Win32.Instally.K@6lne20
DrWebAdware.Downware.17547
McAfee-GW-EditionGenericRXGH-GH!00AD7DF14BEF
SophosGeneric PUA NC (PUA)
IkarusPUA.Instally
GDataGen:Variant.Adware.Mikey.49900
JiangminDownloader.Kasinst.ab
AviraHEUR/AGEN.1104074
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASBOL.9867
ArcabitTrojan.Adware.Mikey.DC2EC
MicrosoftTrojan:Win32/Occamy.C3F
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Helper.R187469
BitDefenderThetaGen:NN.ZexaF.34084.lv0@a4pO1Gji
ALYacGen:Variant.Adware.Mikey.49900
VBA32BScope.Downloader.Kasinst
MalwarebytesAdware.Agent
RisingTrojan.Generic@ML.91 (RDML:0kmCZmdzD2W44XjDP42LOQ)
YandexTrojan.GenAsa!gsJjFm5yMb0
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Generic.AC.382DC9!tr
AVGFileRepMalware
Cybereasonmalicious.14bef7
PandaTrj/Genetic.gen

How to remove Adware.Mikey.49900?

Adware.Mikey.49900 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment