Malware

Midie.99753 information

Malware Removal

The Midie.99753 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.99753 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Suspicious wmic.exe use was detected

How to determine Midie.99753?


File Info:

name: 74BF9176B561BBAD9686.mlw
path: /opt/CAPEv2/storage/binaries/438bf7fa51360faf2b1816a1170db0109d989bd4a4c096531def31280d8a2616
crc32: 0B2DCE49
md5: 74bf9176b561bbad96862854d4a2084d
sha1: 86726a74efb2940421e985c42124540b05b4436b
sha256: 438bf7fa51360faf2b1816a1170db0109d989bd4a4c096531def31280d8a2616
sha512: 314df68cab60f318da30af4883e3f757355b258b2a30a690327e2fb23b3394068405d547014a2a63892dd09b1e1d591ae2b85a6c7b888df86ba4234cc09f1e32
ssdeep: 24576:7BW40WjbgKeCBOzUzuOCIgeGLIjq5KlkvGgVymY/+dGB:cZWfvIgJCdeGE0Ke+gIm5GB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8451243F7D74475F0294E34C9318400ED677EB91AF1B0593CB9DA0E067A2C69CBABA6
sha3_384: f39123d0d8048190c3c2b8cac7ff55d54ad07540ee6453930771e8d1fc40d71f3940a2755c4943335635ebc950133962
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2016-04-06 14:39:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: UniKey
FileDescription: UniKey 4.3 RC5 Setup
FileVersion:
LegalCopyright:
ProductName: UniKey 4.3 RC5
ProductVersion: 4.3 RC5
Translation: 0x0000 0x04b0

Midie.99753 also known as:

MicroWorld-eScanGen:Variant.Midie.99753
FireEyeGen:Variant.Midie.99753
ALYacGen:Variant.Midie.99753
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/Xegumumune.19cb132c
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R002H07L321
KasperskyTrojan-Spy.Win32.Xegumumune.iko
BitDefenderGen:Variant.Midie.99753
AvastWin32:Malware-gen
TencentWin32.Trojan-spy.Xegumumune.Aiip
Ad-AwareGen:Variant.Midie.99753
EmsisoftGen:Variant.Midie.99753 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosGeneric PUA IG (PUA)
IkarusTrojan.Rozena
GDataGen:Variant.Midie.99753
AviraTR/Spy.Xegumumune.lsfuq
ArcabitTrojan.Midie.D185A9
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!74BF9176B561
MAXmalware (ai score=87)
APEXMalicious
FortinetW32/PossibleThreat
AVGWin32:Malware-gen

How to remove Midie.99753?

Midie.99753 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment