Malware

Midie.113896 (B) removal tips

Malware Removal

The Midie.113896 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.113896 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system

How to determine Midie.113896 (B)?


File Info:

name: 7AFD11ECD0D926D46746.mlw
path: /opt/CAPEv2/storage/binaries/14b5bc6cf728d2ad5514a3e7fce12b0d2be1abe2bd2fb3373a761d01bfb7a156
crc32: DE9020DF
md5: 7afd11ecd0d926d4674648b4538a02ab
sha1: b165167485726e3d719e3d29fc4777415d0b8a68
sha256: 14b5bc6cf728d2ad5514a3e7fce12b0d2be1abe2bd2fb3373a761d01bfb7a156
sha512: 0db8aa6f7d7b4d8ecdc9e9c46f479a21cace17901df06ef70abcc14d4380db74590275402d05da0f23443e563c4ae40a9e2f4e31af49281605f116f6ca79eab5
ssdeep: 12288:MyqkaluCC89o8sS/F/YtmglbVv6TAu/rPf2mw15ez:YbC8FsS/FIlZvbu/pwXez
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170C43303FA8F4E90DFE630B0291302FDAA6BBDB92D01FEC58F45FA8513E6504559256E
sha3_384: c96cb4e63e27f8eaee4bf169ccf6412c9ac446b43b853876ff8eaede1940a9a047ce2ac8375d9719adb825b4a3ecc9c1
ep_bytes: eb05091d33d1b850eb0410b9ba4be811
timestamp: 2022-10-17 12:53:16

Version Info:

FileDescription: Description of my application
InternalName: myfile.exe
OriginalFilename: myfile.exe
CompanyName: My Company
LegalCopyright: © My Company. All rights reserved.
ProductName: My App
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04b0

Midie.113896 (B) also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Midie.113896
ALYacGen:Variant.Midie.113896
CylanceUnsafe
VIPREGen:Variant.Midie.113896
K7AntiVirusTrojan ( 005944981 )
K7GWTrojan ( 005944981 )
Cybereasonmalicious.485726
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.Obsidium.KJ
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.Bandra.gen
BitDefenderGen:Variant.Midie.113896
RisingTrojan.Bandra!8.13457 (TFE:5:FvCYJFKTGUR)
Ad-AwareGen:Variant.Midie.113896
EmsisoftGen:Variant.Midie.113896 (B)
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7afd11ecd0d926d4
SophosML/PE-A
IkarusTrojan.Win32.Obsidium
AviraHEUR/AGEN.1216961
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Midie.D1BCE8
GDataGen:Variant.Midie.113896
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R530014
Acronissuspicious
MAXmalware (ai score=81)
VBA32BScope.Trojan.Packed
MalwarebytesRiskWare.FlyStudio
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34726.Jq1@a4Ytybmi
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Midie.113896 (B)?

Midie.113896 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment