Malware

Midie.72878 information

Malware Removal

The Midie.72878 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.72878 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Midie.72878?


File Info:

crc32: 863D0F3B
md5: d86450524a0af076465816ba39af9bcb
name: visualservice.exe
sha1: dd72bf763b6745a8dc5dc0f0e9cf4e9e27726e15
sha256: 4457d49095a509a84ce5c9796b7470c03a95638e1f628882cb8f6331b0153efb
sha512: cb289cdee204957582af5224599b2d77172abcd8b9c04ef1215326437f5fb60b0a655ef5f2ab536c3f9a54b9e8671049004db9cb887cd1134f8587d8113ece57
ssdeep: 12288:BsCOryB5QNN5JIrumfugKrcvi4nWV36xfvgh:Wb65+JIr1uvY7WF6dgh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1994-2012 Lua.org, PUC-Rio.
FileVersion: 5.1.5
CompanyName: Lua.org
PrivateBuild: Built for LuaDist
Comments: www.lua.org
ProductName: Lua - The Programming Language
ProductVersion: 5.1.5
FileDescription: Lua Console Standalone Interpreter
OriginalFilename: lua.exe

Midie.72878 also known as:

MicroWorld-eScanGen:Variant.Midie.72878
FireEyeGeneric.mg.d86450524a0af076
McAfeeFareit-FTB!D86450524A0A
CylanceUnsafe
K7AntiVirusTrojan ( 005680341 )
BitDefenderGen:Variant.Midie.72878
K7GWTrojan ( 005680341 )
BitDefenderThetaGen:NN.ZelphiF.34126.IG1@aeMGwWdi
F-ProtW32/Agent.NCKD
APEXMalicious
GDataGen:Variant.Midie.72878
KasperskyUDS:DangerousObject.Multi.Generic
Ad-AwareGen:Variant.Midie.72878
Invinceaheuristic
McAfee-GW-EditionFareit-FTB!D86450524A0A
Trapminemalicious.high.ml.score
CyrenW32/Agent.IRZL-3261
Antiy-AVLTrojan/Win32.TSGeneric
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftVirTool:Win32/CeeInject.JJ!bit
AhnLab-V3Suspicious/Win.Delphiless.X2066
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.DLF
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EMHU
RisingTrojan.Injector!8.C4 (TFE:dGZlOgWc0miAoW3COQ)
FortinetW32/Injector.ELXR!tr
Paloaltogeneric.ml
Qihoo-360HEUR/QVM05.1.C6FB.Malware.Gen

How to remove Midie.72878?

Midie.72878 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment