Malware

How to remove “Midie.70514”?

Malware Removal

The Midie.70514 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.70514 virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Sindhi
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
brf1.secondaryservicelog.cloudns.cx

How to determine Midie.70514?


File Info:

crc32: 6E97F0FD
md5: 5299d6c85ccb235325d9c8f59492a70b
name: helpchma.exe
sha1: fe54cc4239718a139cf1f2b33950189de4575424
sha256: d855a19519fc945bfc2f2d2accdb53b7b849f512ecabfa9e865ce615b99e730d
sha512: 4157d53c578e49527446753c147214db10efa9128fb86efb3ca73a49e228c7999ef220dd2169f0fe0df0b45ae172c0ee9907344f9f1ae6705d3bf89d63f48e6e
ssdeep: 3072:yqmzeT5y4xflpvYpRvQzoH1klKVpmvnlBguC14phMWUb6R6WGqYde:yqmzeT5y4F9eNavnncuMtGO
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

0: [No Data]

Midie.70514 also known as:

MicroWorld-eScanGen:Variant.Midie.70514
FireEyeGeneric.mg.5299d6c85ccb2353
Qihoo-360Win32/Trojan.Exploit.a32
McAfeeGenericRXJP-XQ!5299D6C85CCB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Midie.4!c
SangforMalware
BitDefenderGen:Variant.Midie.70514
K7GWTrojan ( 0056088c1 )
Cybereasonmalicious.239718
Invinceaheuristic
APEXMalicious
AvastWin32:DropperX-gen [Drp]
GDataGen:Variant.Midie.70514
KasperskyExploit.Win32.Shellcode.nyt
AlibabaTrojan:Win32/Kryptik.5cc514f2
NANO-AntivirusTrojan.Win32.Kryptik.hauztr
TencentWin32.Exploit.Shellcode.Suxt
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent (A)
F-SecureTrojan.TR/Crypt.Agent.aycfx
DrWebTrojan.PWS.Siggen2.43523
McAfee-GW-EditionBehavesLike.Win32.ZeroAccess.ch
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.AZFD-9374
JiangminExploit.ShellCode.vk
AviraTR/Crypt.Agent.aycfx
ArcabitTrojan.Midie.D11372
ZoneAlarmExploit.Win32.Shellcode.nyt
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.RL_MalPe.R325904
Acronissuspicious
ALYacGen:Variant.Midie.70514
MAXmalware (ai score=81)
Ad-AwareGen:Variant.Midie.70514
MalwarebytesSpyware.AzorUlt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBBY
RisingTrojan.Generic@ML.100 (RDML:vfcE6UnxG4BEddd0btlEyQ)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HBCF!tr
BitDefenderThetaGen:NN.ZexaF.34090.mSW@a4mYHekG
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Midie.70514?

Midie.70514 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment