Malware

Should I remove “Midie.87987”?

Malware Removal

The Midie.87987 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.87987 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

Related domains:

grigblog.club

How to determine Midie.87987?


File Info:

name: ED234E565510650CFBDC.mlw
path: /opt/CAPEv2/storage/binaries/8995a9972f1fb89760b1a7411509c4c16e6a6f2dffe0871445397280d6586428
crc32: 6685751B
md5: ed234e565510650cfbdcbd2e342504d2
sha1: 14a5a215fa5bc45ff2a1fb37b5c4f69980564cc0
sha256: 8995a9972f1fb89760b1a7411509c4c16e6a6f2dffe0871445397280d6586428
sha512: fd829635f7eaa16f6a0342d76e8e6d942f89c8edd703ce23145bc1e1e57dbbf7a33249775f918207d01c2455009ac2e8d5d407ff9160b0a5b2a8b0c13e5fd98d
ssdeep: 196608:fvdqGM8sV9RiZq1eTJec91raPzZMu1RBCWUFoOEOTij/Pkq6NwwpzXduX:8DlSZGeTJec9NarZQW7OHQ/MqBwp7duX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179B62367F249A03EC0AE3B314673A45059FFA669E517BE2627F0C88CCF651C11E3A761
sha3_384: 9ffa6ad509b88e0323be519c305c178c41fca0508d0afc7eeee8db226a2834c3fadceb3cde9c094d5d6f72647719ab72
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2019-04-27 08:22:11

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Software Security System
FileDescription: GBAMatrix 32-bit
FileVersion: 5.0.1.18
LegalCopyright:
OriginalFileName:
ProductName: GBAMatrix
ProductVersion: 5.0.1.18
Translation: 0x0000 0x04b0

Midie.87987 also known as:

LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.87987
McAfeeArtemis!ED234E565510
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.f5c5f2fe
K7GWTrojan ( 005722f11 )
CyrenW32/Trojan.VTKK-8256
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Ekstak.gen
BitDefenderGen:Variant.Midie.87987
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Midie.87987
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGen:Variant.Midie.87987
EmsisoftGen:Variant.Midie.87987 (B)
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.HCW2B9
AviraHEUR/AGEN.1142804
ArcabitTrojan.Midie.D157B3
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.R420631
ALYacGen:Variant.Midie.87987
MAXmalware (ai score=83)
VBA32Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
TencentWin32.Trojan-dropper.Agent.Akyl
MaxSecureTrojan.Malware.73555928.susgen
FortinetRiskware/Ekstak
AVGWin32:Adware-gen [Adw]

How to remove Midie.87987?

Midie.87987 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment