Malware

Midie.107456 (B) removal guide

Malware Removal

The Midie.107456 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.107456 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Midie.107456 (B)?


File Info:

name: 0DBAA66439E59CD1DBB2.mlw
path: /opt/CAPEv2/storage/binaries/ff3ff56966b125389999a6d5c694c8cdcec937bb1dde578270852d0a03fd9b99
crc32: 12B97854
md5: 0dbaa66439e59cd1dbb22b4bbafe099a
sha1: 008c1176107b40c81da076b38fabcc2f722e9cd3
sha256: ff3ff56966b125389999a6d5c694c8cdcec937bb1dde578270852d0a03fd9b99
sha512: 85ce668683f12617daacf056ef3e693d774f96feea1fd15f819f3ef0d4627a24e15ccc14737fd88b0cad5e59556b9f5e3d040b39bd38438017e1542759458c0a
ssdeep: 24576:/lAPwkLf73W7fsE9oxX5b1BCgTvBsmZjWpnnY:/3l7joxJzTS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4259D13E58180F2D414267661F79B35AEB097160E25CED3B7A4DE792C22792EE3B30D
sha3_384: 82fe0c029af73ff51744d3e0fda6a8f63dffaf7f932e1cd6a0c1fab96501bfa3ea68ac97e8115ff01d9c724e62716c9a
ep_bytes: 558bec6aff68d0b64c006884ed480064
timestamp: 2022-01-15 08:44:03

Version Info:

0: [No Data]

Midie.107456 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.0dbaa66439e59cd1
McAfeeGenericRXAA-AA!0DBAA66439E5
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
AlibabaBackdoor:Win32/Saklof.fa7e7b9d
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.439e59
BitDefenderThetaGen:NN.ZexaF.34182.7qW@auYJhLhb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.OLX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Scar-18
KasperskyHEUR:Backdoor.Win32.Saklof.gen
BitDefenderGen:Variant.Midie.107456
NANO-AntivirusRiskware.Win32.FlyStudio.hnvnjh
MicroWorld-eScanGen:Variant.Midie.107456
AvastWin32:Malware-gen
TencentWin32.Backdoor.Saklof.Jcs
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftGen:Variant.Midie.107456 (B)
IkarusTrojan.Win32.FlyAgent
JiangminTrojanDropper.Dinwod.tq
AviraBDS/Redcap.shpoy
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Woreflint.A!cl
GDataWin32.Trojan.Flyagent.A
VBA32BScope.Trojan.Dynamer
ALYacGen:Variant.Midie.107456
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.FlyStudio
RisingSpyware.KeyLogger!1.65B5 (CLASSIC)
YandexTrojan.GenAsa!DTDJ/jK7DWk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Midie.107456 (B)?

Midie.107456 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment