Malware

Midie.92257 removal instruction

Malware Removal

The Midie.92257 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.92257 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
www.ytddownloader.com
a.tomx.xyz
telete.in
apps.identrust.com

How to determine Midie.92257?


File Info:

crc32: 34DC0B32
md5: 534d0c4c689c99de5fa06068311f10d3
name: 534D0C4C689C99DE5FA06068311F10D3.mlw
sha1: 3639f3b7635e692ea3a397d34a37cdd771c4ed73
sha256: 05fd359e1bbd54a0884da07fc0f09eb66c86c9059e492efc9c9376fbf6469eee
sha512: 8445e8641e18f69351989f98d23883bc85ac58d8b322ad93395117375f8dcecaf2d18f4de54571dc826f1c1789fbfd97ac3cd09ff8918131bb33cf1c9b1bb5c8
ssdeep: 196608:5utpW72KEhMq2zUS+Wdr+qPYoatl0+t/7I9K6Td+70oeQNEZhp7LdCQMGjwQM7lW:Y62HhM9JXdKqPQzcY6k7uQEF7EjlrcL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2021 YTD Video Downloader. Limited. All Rights Reserved.
FileVersion: 5.9.18.8
CompanyName: 2021 YTD Video Downloader. Limited. All Rights Reserved.
Comments: This installation was built with Inno Setup.
ProductName: YTD Video Downloader Pro v5.9.18.8 + Fix
ProductVersion: 5.9.18.8
FileDescription: YTD Video Downloader Pro v5.9.18.8 + Fix Setup
OriginalFileName:
Translation: 0x0000 0x04b0

Midie.92257 also known as:

Elasticmalicious (high confidence)
DrWebAdware.Downware.19948
ALYacGen:Variant.Midie.92257
CyrenW32/YTDloader.B.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/YTDDownloader.H potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyTrojan.Win32.Telebot.h
BitDefenderGen:Variant.Midie.92257
NANO-AntivirusTrojan.Win32.Telebot.iwfbtd
MicroWorld-eScanGen:Variant.Midie.92257
Ad-AwareGen:Variant.Midie.92257
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGen:Variant.Midie.92257
EmsisoftGen:Variant.Midie.92257 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1141029
Antiy-AVLTrojan/Generic.ASMalwS.30861D5
KingsoftWin32.Troj.Telebot.h.(kcloud)
MicrosoftTrojan:Script/Phonzy.C!ml
GDataGen:Variant.Midie.92257
AhnLab-V3Trojan/Win.Generic.C4529411
McAfeeArtemis!534D0C4C689C
MAXmalware (ai score=81)
VBA32BScope.Adware.Downware
PandaTrj/CI.A
RisingTrojan.Generic@ML.94 (RDML:E6wBot0PBSzrrIi2KJ5SYg)
YandexRiskware.Agent!d+lfchOy8iU
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:Adware-gen [Adw]

How to remove Midie.92257?

Midie.92257 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment