Malware

What is “Mikey.115089”?

Malware Removal

The Mikey.115089 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.115089 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Checks for the presence of known windows from debuggers and forensic tools

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mikey.115089?


File Info:

crc32: 8A76B641
md5: 49d24fc12ccba3d412757a18039fff16
name: upload_file
sha1: d7182be789f06d348bfe0aaff0ca2da7e1fedf2d
sha256: e812d2f7858c5971f4f6f56e7449eeaf682863dde440dd903ae93ddaaafa2002
sha512: b292edc57dc4cc870f65376eb8debecff0e2eb0118df803d4c55fbe60ca8557ccba664342d55ba391efdb07eaf0000ef4722b6544ae7e0dc13b73b67ff207b0e
ssdeep: 12288:cfjuCI5kFKR3xLpeJz8FXrAqQwsgx13gNsl2KZquoljauh0Nplns+Tg1:vl3kJz4XrpQwXx5gNsl2KQJZ++
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x9189x68a6
Translation: 0x0804 0x04b0

Mikey.115089 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.300
MicroWorld-eScanGen:Variant.Mikey.115089
FireEyeGeneric.mg.49d24fc12ccba3d4
McAfeePacked-NU!49D24FC12CCB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 004b942f1 )
BitDefenderGen:Variant.Mikey.115089
K7GWAdware ( 004b942f1 )
Cybereasonmalicious.12ccba
InvinceaMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34282.Qm0@aqgcPYib
CyrenW32/Trojan.FOBA-8427
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
AlibabaRansom:Win32/Foreign.c756683e
ViRobotTrojan.Win32.Z.Graftor.695856
AegisLabTrojan.Win32.Generic.kYXw
Ad-AwareGen:Variant.Mikey.115089
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
F-SecureTrojan.TR/Crypt.ZPACK.Gen
TrendMicroTrojan.Win32.WACATAC.USMANJ220
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
EmsisoftGen:Variant.Mikey.115089 (B)
SentinelOneDFI – Malicious PE
GDataWin32.Application.PUPStudio.A
JiangminTrojan.AddUser.h
MaxSecureDropper.Dinwod.frindll
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=99)
ArcabitTrojan.Mikey.D1C191
MicrosoftPUA:Win32/Vigua.A
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Fuerboos
ALYacTrojan.Ransom.MBRlock
PandaW32/Sality.AA
ESET-NOD32a variant of Win32/MBRlock.BA
TrendMicro-HouseCallTrojan.Win32.WACATAC.USMANJ220
RisingRansom.MBRLocker!1.B2B2 (CLASSIC)
YandexTrojan.MBRlock!R+oFjnD0IhI
IkarusTrojan.Win32.MBRlock
FortinetW32/Generic.AP.10DA2E!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Trojan.Generic

How to remove Mikey.115089?

Mikey.115089 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment