Malware

About “Midie.77325 (B)” infection

Malware Removal

The Midie.77325 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.77325 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Midie.77325 (B)?


File Info:

name: 0A749D7C5B98E7D3FB3D.mlw
path: /opt/CAPEv2/storage/binaries/821154a827381a063e6b6ed529658e8c8147f739abea9653e1e24c047e3f5083
crc32: DD097E06
md5: 0a749d7c5b98e7d3fb3d91549d617eec
sha1: 6e387847ec88b88b79253bc18dacb8bc7a4f0b99
sha256: 821154a827381a063e6b6ed529658e8c8147f739abea9653e1e24c047e3f5083
sha512: dc96e324db41b736f19903a6908da1450ea28b0b7c729c0a8c66cafe95f7f09fd28ff01f1227c68d187da51d5b63e3bc54f504ffb2c7cf881ff64a65c24bdeda
ssdeep: 6144:eHtzz3lZiu5dqmYN1v4579/piV1POH1f+9GolHSfHXovNvunQyMqtnh/wqJ:EE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED34ACBB3BC029C5CEE250FFB2B5C47788893439075F017475B19DE0796CA25E299AE2
sha3_384: bd4933e6c98cc3dc20be98f274aaf90cb605b1fa9d4dec23afe65f54cb6ce33d854fee8496df1cdf242bf786fa6a9cb4
ep_bytes: 68a8114000e8eeffffff000000000000
timestamp: 2010-11-09 12:48:26

Version Info:

Translation: 0x0409 0x04b0
ProductName: CPPBZ12
FileVersion: 6.38
ProductVersion: 6.38
InternalName: CPPBZa
OriginalFilename: CPPBZa.exe

Midie.77325 (B) also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner1.30887
MicroWorld-eScanGen:Variant.Midie.77325
ClamAVWin.Trojan.VB-1326
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.dt
McAfeeDownloader-CJX.gen.j
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003325f51 )
K7GWEmailWorm ( 003325f51 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36744.om0@auXVAZci
VirITWorm.Win32.Generic_c.BHD
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.WR
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VBKrypt.csjv
BitDefenderGen:Variant.Midie.77325
NANO-AntivirusTrojan.Win32.VB2.cojasf
AvastWin32:AutoRun-BSB [Wrm]
TencentWorm.Win32.Wbna .16000410
EmsisoftGen:Variant.Midie.77325 (B)
F-SecureTrojan.TR/VB.FCE
BaiduWin32.Worm.AutoRun.cj
VIPREGen:Variant.Midie.77325
TrendMicroWORM_VBNA.SMCY
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.0a749d7c5b98e7d3
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Midie.77325
JiangminTrojan/VBKrypt.hcoz
GoogleDetected
AviraTR/VB.FCE
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.VB.ww@2ajsup
ArcabitTrojan.Midie.D12E0D
ViRobotTrojan.Win32.A.VBKrypt.233472.F
ZoneAlarmTrojan.Win32.VBKrypt.csjv
MicrosoftWorm:Win32/Vobfus!pz
VaristW32/Vobfus.K.gen!Eldorado
AhnLab-V3Trojan/Win32.VBKrypt.R5677
VBA32Trojan.VBRA.03956
ALYacGen:Variant.Midie.77325
TACHYONTrojan/W32.VB-VBKrypt.233472.AH
Cylanceunsafe
PandaW32/Vobfus.FJ
TrendMicro-HouseCallWORM_VBNA.SMCY
RisingWorm.VobfusEx!1.99EB (CLASSIC)
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
AVGWin32:AutoRun-BSB [Wrm]
Cybereasonmalicious.7ec88b
DeepInstinctMALICIOUS

How to remove Midie.77325 (B)?

Midie.77325 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment