Malware

Midie.105973 removal

Malware Removal

The Midie.105973 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.105973 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Midie.105973?


File Info:

name: 6CB5092F442B6636B15F.mlw
path: /opt/CAPEv2/storage/binaries/70a8bb55a9782e13f26edc504ea794a07e639a498462722cf2b9cd072f44bdb6
crc32: B735C8A8
md5: 6cb5092f442b6636b15fc7a70c38411f
sha1: 0cbe6c77f77e0e36d6e40895af25e1714fcbadf6
sha256: 70a8bb55a9782e13f26edc504ea794a07e639a498462722cf2b9cd072f44bdb6
sha512: 39c9e5d501e7ac50cf6a9a11bf9d3a614e77a43a40938055deec5da2b863273a76255b30bfc28eeeec2ac153c019b63a119663d31482a6172a848641d04c86ee
ssdeep: 6144:q4L26SdV14le9kJhZiwhac/tWlGQqv8B:q4iZdVihkaac0v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144A4F21A79A1D933D4EA97B37A75C2C0497BBD052A60428BB7477F6F7B312C04A66303
sha3_384: fdb80462465ffe85453021154a8c6f6188d2247c7a7cbc47b67bcf10a33af0faed04b12419c8229ca80de8c6f97e76c7
ep_bytes: e8a92d0000e979feffff8bff558bec8b
timestamp: 2020-07-30 22:40:31

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.14.72.77
Translation: 0x0129 0x07bc

Midie.105973 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.trW9
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.6cb5092f442b6636
CAT-QuickHealTrojan.ConvagenPMF.S25706310
McAfeeLockbit-FSWW!6CB5092F442B
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3660130
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/StopCrypt.46b58018
K7GWTrojan ( 0058c2741 )
K7AntiVirusTrojan ( 0058c2741 )
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNUD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-9917126-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Midie.105973
MicroWorld-eScanGen:Variant.Midie.105973
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan-spy.Stealer.Wskj
EmsisoftTrojan.Crypt (A)
DrWebTrojan.PWS.Stealer.31749
TrendMicroTROJ_GEN.R002C0PLN21
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
SophosMal/Generic-R + Mal/Agent-AWV
IkarusTrojan.Win32.Crypt
JiangminBackdoor.Tofsee.fhy
AviraTR/Crypt.Agent.dweuz
Antiy-AVLTrojan/Generic.ASMalwS.34F83EB
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/StopCrypt.PU!MTB
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataWin32.Trojan.BSE.1I89TIO
AhnLab-V3Infostealer/Win.Raccoon.R460127
VBA32BScope.Trojan.Agent
ALYacGen:Variant.Midie.105973
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002C0PLN21
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazrCzOh0+Pv2gFMoKTS9vhHl)
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.ERHN!tr
BitDefenderThetaGen:NN.ZexaF.34182.CuW@aihtE9mK
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.7f77e0
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Midie.105973?

Midie.105973 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment