Malware

What is “Midie.104944”?

Malware Removal

The Midie.104944 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.104944 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Midie.104944?


File Info:

name: 1A05598133823664C5AC.mlw
path: /opt/CAPEv2/storage/binaries/7e922f7141d3496d27c2c40232845494d4fe5a46265198eb225df080804755c5
crc32: A2F5D1D2
md5: 1a05598133823664c5acb0bd01c5109f
sha1: 4070275d3155a7f8787e1fe04aa0c0e9bf420f27
sha256: 7e922f7141d3496d27c2c40232845494d4fe5a46265198eb225df080804755c5
sha512: eb04a2e455c46cb0e953d895695ba4f0e74baca11d5338329abf543c0fffa93607eccfc2cf342e7a3b248adecd4601fa8fae7e2112fa01f3c6aac4046915b999
ssdeep: 12288:dbcWcpQUx0A5WLJwFc58H5sS4tacMvJVfT/e/28G532ulud9jUOE6sL:dbcWhUx0A5WLJ0PHt4tanVZxHk9oOE6s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154C4E022B142D032E5AD3DB1D775A7A95A3124B23E1F2687F7498BF20A903D1D71874F
sha3_384: 3de3055c944bd4e50e52c079b93577791adae01d26ad67fb36a318a3443e9104bd81bc40066f29880d5417dfd32e2932
ep_bytes: e829c70000e978feffffcccccccc8b4c
timestamp: 2017-01-24 02:57:10

Version Info:

CompanyName: Microsoft Corporation
FileDescription: DNSCache Unattend Generic Command
FileVersion: 6.1.7601.24168 (win7sp1_ldr.180608-0600)
InternalName: dnscacheugc.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dnscacheugc.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.24168
Translation: 0x0409 0x04b0

Midie.104944 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.12917
MicroWorld-eScanGen:Variant.Midie.104944
FireEyeGeneric.mg.1a05598133823664
McAfeeGenericRXQW-VK!1A0559813382
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderThetaGen:NN.ZexaF.34084.JC1@a4O7gB
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNPZ
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Deapax.gen
BitDefenderGen:Variant.Midie.104944
AvastWin32:Zberp-A [Trj]
TencentMalware.Win32.Gencirc.10cf9498
Ad-AwareGen:Variant.Midie.104944
SophosML/PE-A + Mal/Kryptik-DC
ZillyaTrojan.Foreign.Win32.59819
McAfee-GW-EditionBehavesLike.Win32.TrojanGoznym.hc
EmsisoftGen:Variant.Midie.104944 (B)
GDataGen:Variant.Midie.104944
JiangminTrojan.Deapax.bl
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.34DACCC
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R455608
Acronissuspicious
VBA32BScope.Trojan.Encoder
ALYacGen:Variant.Midie.104944
MAXmalware (ai score=88)
MalwarebytesMalware.AI.1133455
APEXMalicious
RisingTrojan.Generic@ML.90 (RDML:pdPzaJ2yzZSuijoZxtiOlg)
YandexTrojan.Agent!sy1fCytIaSc
AVGWin32:Zberp-A [Trj]
Cybereasonmalicious.d3155a

How to remove Midie.104944?

Midie.104944 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment