Malware

Midie.140131 removal guide

Malware Removal

The Midie.140131 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.140131 virus can do?

  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Midie.140131?


File Info:

name: DCFE2DDCB8B26987F1A2.mlw
path: /opt/CAPEv2/storage/binaries/0278965db82a7947eb53f87d9d8fbdb7d0ea921595d67b0e4f5c763e80295370
crc32: 50FD3551
md5: dcfe2ddcb8b26987f1a2d6eb76a8a680
sha1: 3e887192a03245a24d0e280b32eab7ac5b3202d0
sha256: 0278965db82a7947eb53f87d9d8fbdb7d0ea921595d67b0e4f5c763e80295370
sha512: 6c1f866585b52c9dac7817c3196e7488624a2898f8b0e6edd769ff4e6b8df1f48acf6fb873256b535ae3f39059b537fb040611cdf988d3c93f5d40fddd428560
ssdeep: 6144:RMWeO6Q5rm1rxDsU1QMpBVmsxmQbozPzRsB4nqYqFc0jbqRp1NGB00q03fLIkmOq:eWP15Q9LOMpnBw6o7KmdznIB0ILI07
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153D47E12B6F244F5C62A253209BA2735E975EB030B25CFC39365DEFC2C36961AE37125
sha3_384: b8db1074bba88f7ddb44e801b43d6eccdfaabe4961ba1ba3982db354cd9c91e2512b8fe19991b285694ec5fc2301dd91
ep_bytes: 558bec6aff6870044800686c85450064
timestamp: 2013-04-28 22:39:09

Version Info:

0: [No Data]

Midie.140131 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.ltZz
CynetMalicious (score: 100)
FireEyeGeneric.mg.dcfe2ddcb8b26987
CAT-QuickHealRisktool.Flystudio.16886
SkyhighBehavesLike.Win32.Generic.jh
ALYacGen:Variant.Midie.140131
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRiskWare:Win32/FlyStudio.05a56d86
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
ArcabitTrojan.Midie.D22363
BitDefenderThetaGen:NN.ZexaF.36608.NqW@aa55mHhb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
APEXMalicious
ClamAVWin.Malware.Qqpass-9877089-0
Kasperskynot-a-virus:UDS:RiskTool.Win32.FlyStudio.duk
BitDefenderGen:Variant.Midie.140131
MicroWorld-eScanGen:Variant.Midie.140131
AvastWin32:Malware-gen
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Midie.140131
TrendMicroTROJ_GEN.R002C0PKP23
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Midie.140131 (B)
IkarusTrojan.Crypt
JiangminBackdoor/Blackhole.cyz
VaristW32/A-b0178058!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmnot-a-virus:RiskTool.Win32.FlyStudio.duk
GDataWin32.Application.PSE.1OV7PVV
GoogleDetected
McAfeeGenericRXBC-JR!DCFE2DDCB8B2
MAXmalware (ai score=83)
VBA32BScope.Trojan.Rootkit
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0PKP23
RisingTrojan.Generic@AI.99 (RDML:dH78n+/K/B5+pGBjGx/ysA)
YandexTrojan.GenAsa!fZKvVA7bu5s
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Malware-gen
Cybereasonmalicious.2a0324
DeepInstinctMALICIOUS

How to remove Midie.140131?

Midie.140131 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment