Malware

Midie.6956 (B) information

Malware Removal

The Midie.6956 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.6956 (B) virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Midie.6956 (B)?


File Info:

crc32: 259578D9
md5: ffdfcf4b1ce15343f15b36a23ddee7fe
name: FFDFCF4B1CE15343F15B36A23DDEE7FE.mlw
sha1: 09fb4a4b171df174465c38a617cc06acf79f4ea8
sha256: 95d181e9a2d5e3a8a966a9c0dd07c5a440d84b8349a7e99606bbb94101be0d77
sha512: 6460ad3584f8e774b9f0b652b37d04d76d70f9628dc7b123396fbb7aeb6559cc696ea755a6dcc9a609c2088ad9f5146c0e18ce1d3854fe798b08aa262e5b0c3c
ssdeep: 24576:rOXFn7n+brAnvgER6GSqrCJGRzatThRiVNbLGJv6plFh9iGa2oMYMgdsHGY:6VD+b8nDMGtuE8TjFJspDLoVMgdkR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Mozilla
InternalName: 7zS.sfx
FileVersion: 18.05
CompanyName: Mozilla
ProductName: Firefox
ProductVersion: 18.05
FileDescription: Firefox
OriginalFilename: 7zS.sfx.exe
Translation: 0x0409 0x04b0

Midie.6956 (B) also known as:

K7AntiVirusTrojan ( 003dc1641 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.58694
CynetMalicious (score: 100)
CAT-QuickHealTrojanToga.MUE.R9
ALYacGen:Variant.Midie.6956
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.6167
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 003dc1641 )
Cybereasonmalicious.b1ce15
BaiduWin32.Trojan-Dropper.Injector.f
SymantecW32.Faedevour!inf
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PYF
APEXMalicious
AvastWin32:Zbot-THZ [Trj]
ClamAVWin.Malware.Bzub-6727003-0
KasperskyBackdoor.Win32.Androm.qxe
BitDefenderGen:Variant.Midie.6956
NANO-AntivirusTrojan.Win32.Androm.ctymsi
ViRobotWin32.Daws.B
MicroWorld-eScanGen:Variant.Midie.6956
TencentBackdoor.Win32.Androm.qxe
Ad-AwareGen:Variant.Midie.6956
SophosML/PE-A + Troj/Mdrop-JIJ
ComodoTrojWare.Win32.Toga.PYF@7g9q1h
F-SecureTrojan.TR/Dropper.Gen
TrendMicroBKDR_ANDROM_HA050002.UVPM
McAfee-GW-EditionPWSZbot-FIB!FFDFCF4B1CE1
FireEyeGeneric.mg.ffdfcf4b1ce15343
EmsisoftGen:Variant.Midie.6956 (B)
JiangminTrojanDropper.Daws.byh
AviraTR/Dropper.Gen
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan[Backdoor]/Win32.Androm.qxe
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Midie.D1B2C
ZoneAlarmBackdoor.Win32.Androm.qxe
GDataWin32.Trojan.PSE.17X5OXT
Acronissuspicious
McAfeePWSZbot-FIB!FFDFCF4B1CE1
MAXmalware (ai score=80)
VBA32BScope.Trojan.Autoit
MalwarebytesBackdoor.Andromeda
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ANDROM_HA050002.UVPM
RisingDropper.Agent!1.AF79 (CLASSIC)
YandexTrojan.GenAsa!zFH4sqyAwHU
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Injector.AQV!tr
AVGWin32:Zbot-THZ [Trj]
Paloaltogeneric.ml

How to remove Midie.6956 (B)?

Midie.6956 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment