Malware

How to remove “Midie.138849”?

Malware Removal

The Midie.138849 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.138849 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Midie.138849?


File Info:

name: FA6CDF03F6B7C989B3F3.mlw
path: /opt/CAPEv2/storage/binaries/544bcf7a235daf223926b3b2611a26dd2fecfa514132cf14b1f533ace7618d89
crc32: 25088CC3
md5: fa6cdf03f6b7c989b3f3a2c115611ef0
sha1: c29063dc4e812cfba61ebc3dddc27f9f318f7068
sha256: 544bcf7a235daf223926b3b2611a26dd2fecfa514132cf14b1f533ace7618d89
sha512: 4695d4466ecd61fb37193caee72dabd50190707376398bac844b54c20caea569219927192dd15b226986397a2d40812cadb15385ea7dc301cb3e3689e49f3e83
ssdeep: 24576:ZDAWFXA+6FmCzt/+5EWFSTx2lTZaqdiXSp0c02uFG6dAk3CMf:liN+HOwlTZaqdwk0c05HGif
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C285C013A2C184B1E619163205BF1739AD7897664931CE83F79CDCFA6F72362AA3710D
sha3_384: 46319adcaed90dd5990aa6ef5951ae8cb60f0399c9115ebeed128337c0bb9dd22238c1ee315d68ab3d1feeddf0550f5b
ep_bytes: 558bec6aff683872590068247a490064
timestamp: 2013-04-04 11:20:11

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Midie.138849 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.mnQ7
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Midie.138849
ClamAVWin.Trojan.Flystudio-9943951-0
FireEyeGeneric.mg.fa6cdf03f6b7c989
ALYacGen:Variant.Midie.138849
Cylanceunsafe
VIPREGen:Variant.Midie.138849
SangforInfostealer.Win32.QQPass.Vb4y
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Midie.138849
K7GWTrojan ( 005886601 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Midie.D21E61
BitDefenderThetaGen:NN.ZexaF.36608.Tr0@aKHMuUfb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.QQPass.NYC
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Sdum.gen
AlibabaTrojanPSW:Win32/QQPass.12d31400
NANO-AntivirusTrojan.Win32.QQPass.dfuvzp
RisingStealer.QQPass!8.F7 (TFE:5:3vpVBEPQpaM)
SophosMal/Generic-S
F-SecureTrojan.TR/PSW.QQpass.jcasa
TrendMicroTROJ_GEN.R002C0PKR23
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/PSW.QQpass.jcasa
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
GDataWin32.Trojan.PSE.11SCEUB
VaristW32/OnlineGames.HG.gen!Eldorado
TACHYONTrojan/W32.Agent.1798144.CI
DeepInstinctMALICIOUS
VBA32BScope.Downloader.Snojan
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PKR23
TencentWin32.Trojan-PSW.2.Uwhl
IkarusTrojan-PSW.QQpass
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Malware-gen
Cybereasonmalicious.c4e812
AvastWin32:Malware-gen

How to remove Midie.138849?

Midie.138849 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment