Malware

About “Midie.84631” infection

Malware Removal

The Midie.84631 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.84631 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Midie.84631?


File Info:

name: 2F968010E2E8130452E6.mlw
path: /opt/CAPEv2/storage/binaries/3f41b446e35721d1cbbdec6d4858e7891ba2cefe4189c167abc47b4a907f794e
crc32: B7DEB781
md5: 2f968010e2e8130452e6b5368e66f5e3
sha1: 0a0bc0a00514ff2948dbd6d7375c4140d2ebc92a
sha256: 3f41b446e35721d1cbbdec6d4858e7891ba2cefe4189c167abc47b4a907f794e
sha512: ad60c74caaf662b61ec193cf3995ff95f4e5d8f4db0e552dc7f709825f63ceb2069a06ea3d26c32e1eee6207ff352a048ab351c2e56ad2abe74ad5be64cf8ae5
ssdeep: 6144:XhTqIDb7H0AHQGFgaQWanmZcV3RrDYDk0pLkZZTTh:oIDUAHQGFgJpn0ipD6RkPJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F548D1FB3649A73E64A80F12E05E76842DDB834275D650FE3D0A71B66F93C6832136B
sha3_384: 7d47b96ade13866dbe66a6d8340cdddd0ffc45b289c3c1a6124175cb68d50a04c129037ac2fc13e691d57be45e2d07c0
ep_bytes: 6854274000e8eeffffff000000000000
timestamp: 2012-06-23 19:17:44

Version Info:

Translation: 0x0409 0x04b0
Comments: Professional Icon Editor
CompanyName: IcoFX Software
FileDescription: IcoFX - The Professional Icon Editor
ProductName: Professional Icon Editor
FileVersion: 2.02.0001
ProductVersion: 2.02.0001
InternalName: IcoFX2
OriginalFilename: IcoFX2.exe

Midie.84631 also known as:

LionicTrojan.Win32.Zbot.l!c
DrWebTrojan.PWS.Panda.655
MicroWorld-eScanGen:Variant.Midie.84631
FireEyeGeneric.mg.2f968010e2e81304
ALYacGen:Variant.Midie.84631
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.107122
SangforVISUAL BASIC4
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaTrojanSpy:Win32/Vilsel.78d594b6
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.0e2e81
BitDefenderThetaGen:NN.ZevbaF.34592.rmW@aCP3qIai
VirITTrojan.Win32.Panda.ZF
CyrenW32/PWS.STRG-6167
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
KasperskyTrojan-Spy.Win32.Zbot.sbqn
BitDefenderGen:Variant.Midie.84631
NANO-AntivirusTrojan.Win32.Zbot.dybqpr
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114c2586
Ad-AwareGen:Variant.Midie.84631
EmsisoftGen:Variant.Midie.84631 (B)
ComodoMalware@#3dmxyd92izu8z
VIPREGen:Variant.Midie.84631
TrendMicroTSPY_JORIK_BL130143.TOMC
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Zbot-CDI
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Midie.84631
JiangminTrojanSpy.Zbot.ewvg
GoogleDetected
AviraTR/PSW.Zbot.289
Antiy-AVLTrojan/Generic.ASMalwS.644
KingsoftWin32.Heur.KVM011.a.(kcloud)
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Zbot.286720.F
McAfeePWS-Zbot.gen.oj
MAXmalware (ai score=100)
VBA32Trojan.VB.Icofix
TrendMicro-HouseCallTSPY_JORIK_BL130143.TOMC
RisingTrojan.Win32.Generic.12DD7DD7 (C64:YzY0OlwhOu3S4buP)
YandexTrojan.GenAsa!K4nCzoCOXE8
IkarusTrojan.Win32.Vilsel
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Vilsel.TET!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Midie.84631?

Midie.84631 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment