Malware

Mikey.115835 removal instruction

Malware Removal

The Mikey.115835 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.115835 virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 0.0.0.0:19730
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Connects to an IRC server, possibly part of a botnet
  • Created a service that was not started
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

tta.monerorx.com
xz.monerogb.com
dns.monerogb.com
gxxs.monerogb.com
ip.3322.net
gx1.monerogb.com

How to determine Mikey.115835?


File Info:

crc32: E5642EEC
md5: e33202ce186c36f7cf16b02c7cde6c0c
name: E33202CE186C36F7CF16B02C7CDE6C0C.mlw
sha1: 38144c0b77a914ecdd9c088b148add6276536f3c
sha256: 938d4a7cc13998c9a316419c90559cc3e846e6d057572a360e017d09bfb9be03
sha512: 460b5369668cb9d3af366a775f35a7bb2b78749157bcb8bfeb2a4aa6f9323dec08ac81cc999bed17c61654416d1caa6fa23873df9a45a9f51c3576a7c739052d
ssdeep: 24576:QKlrsUNPggAatriglEIZ+dglFy5p42StDAN23/tR9g1r5:QKOIPvli8bZ+i/g42StUNaq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: csfe
FileVersion: 1.0.0.0
CompanyName: csfe
Comments: ddd
ProductName: dd
ProductVersion: 1.0.0.0
FileDescription: ddd
Translation: 0x0804 0x04b0

Mikey.115835 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f54a1 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Sdbot.34272
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.GenericRI.S16223057
ALYacGen:Variant.Mikey.115835
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0040f54a1 )
Cybereasonmalicious.e186c3
CyrenW32/A-8128ee96!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Mikey.115835
NANO-AntivirusVirus.Win32.Agent.dvixmz
MicroWorld-eScanGen:Variant.Mikey.115835
TencentWin32.Trojan-gamethief.Magania.Ahnu
Ad-AwareGen:Variant.Mikey.115835
SophosML/PE-A + W32/Pidgeon-A
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34692.7u0@aSIQHxob
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R01FC0DEQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.e33202ce186c36f7
EmsisoftGen:Variant.Mikey.115835 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Farfli.hjqcz
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Zegost.DF!bit
GridinsoftTrojan.Win32.Packed.dd!n
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataGen:Variant.Mikey.115835
AhnLab-V3Trojan/Win32.RL_CoinMiner.R352671
Acronissuspicious
McAfeeFlyagent.d
MAXmalware (ai score=82)
VBA32TrojanPSW.Magania
MalwarebytesAdware.ChinAd
TrendMicro-HouseCallTROJ_GEN.R01FC0DEQ21
RisingBackdoor.Generic!8.CE (TFE:dGZlOgWQCnTfQRTOZg)
IkarusTrojan.Tonmye
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.BELF!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Mikey.115835?

Mikey.115835 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment