Malware

What is “Midie.6956”?

Malware Removal

The Midie.6956 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.6956 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Midie.6956?


File Info:

crc32: 9774F997
md5: 706e9627c62fc6a2b84034d5621c810f
name: 706E9627C62FC6A2B84034D5621C810F.mlw
sha1: 1326ed10e7ace589ca535db1b1d831531de44eaa
sha256: 1a4fa2bef9ba6d8dad38d64eaf4fac916efde79ae88f199323600b546c987f74
sha512: c4fa74676b52e48cfe4b4d487b158f7ada513319f5be42eee5dd10cf420e1db91169b8b723691dbe4aa0cfb47fdc70d4cbbb0e568ec7145ef6ac5721d143e8d8
ssdeep: 49152:pRAZ1CtbTChxKCnFnQXBbrtgb/iQvu0UHOagB:pRi1Ct6hxvWbrtUTrUHOH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Midie.6956 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.6956
FireEyeGeneric.mg.706e9627c62fc6a2
CAT-QuickHealTrojanToga.MUE.R9
McAfeePWSZbot-FIB!706E9627C62F
CylanceUnsafe
VIPRETrojan-Dropper.Win32.Daws.awfy (v) (not malicious)
K7AntiVirusTrojan ( 003fa0611 )
BitDefenderGen:Variant.Midie.6956
K7GWTrojan ( 003fa0611 )
Cybereasonmalicious.7c62fc
TrendMicroTROJ_INJECTOR_FD130021.UVPM
BaiduWin32.Trojan-Spy.Agent.a
CyrenW32/A-757af715!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Bzub-6727003-0
KasperskyHEUR:Backdoor.Win32.Androm.gen
NANO-AntivirusTrojan.Win32.Sysn.esfwcb
ViRobotWin32.Daws.A
TencentTrojan.Win32.Daws.a
Ad-AwareGen:Variant.Midie.6956
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDropper.Daws.AWYG@4xnj8v
F-SecureTrojan.TR/Drop.Daws.awfy
DrWebBackDoor.KCNA.13
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.vc
EmsisoftGen:Variant.Midie.6956 (B)
IkarusWin32.Outbreak
JiangminTrojan.Inject.bcwk
AviraTR/Drop.Daws.awfy
MAXmalware (ai score=84)
Antiy-AVLTrojan[Dropper]/Win32.Daws.awfy
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.D1!ml
ArcabitTrojan.Midie.D1B2C
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
GDataGen:Variant.Midie.6956
CynetMalicious (score: 100)
AhnLab-V3Win32/Pondre.X816
Acronissuspicious
VBA32BScope.Trojan.Autoit
ALYacGen:Variant.Midie.6956
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PYF
TrendMicro-HouseCallTROJ_INJECTOR_FD130021.UVPM
RisingVirus.WdExt!1.CBDC (CLASSIC)
YandexTrojan.GenAsa!zFH4sqyAwHU
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.AQV!tr
BitDefenderThetaGen:NN.ZexaF.34634.CsZ@ay40DTij
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Virus.Win32.WdExt.A

How to remove Midie.6956?

Midie.6956 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment