Malware

How to remove “Mikey.120563”?

Malware Removal

The Mikey.120563 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.120563 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

Related domains:

csdw.jia-si.cn
wpad.local-net
www.jia-si.cn
downdcdn.jia-si.cn

How to determine Mikey.120563?


File Info:

name: A56EA7CBC036A892BEA5.mlw
path: /opt/CAPEv2/storage/binaries/22d7b891bb965b6a0f4b5606152d67f9af5659edcb84a3bbf6fc81cca232f6f1
crc32: B5FAE24E
md5: a56ea7cbc036a892bea5c722d7126b7c
sha1: 7a8fbc1ee66f378f9d507ae7257b549afd9011c7
sha256: 22d7b891bb965b6a0f4b5606152d67f9af5659edcb84a3bbf6fc81cca232f6f1
sha512: ed740dc4e67a1cdbaa1feb7785c29970bab4ef0115eacffa379cdf38823ef22994ab7d99af540af15eeeb8b4f751b09c388a8dcd991f663a0c494e22bcc8b243
ssdeep: 49152:vyOvVizZVjOnKU+RdZH2AIb5u82MM2wBDvk3Fi/cyPw40a07PqCSIh2exhK:vywkzZVjOKPFrku82MMvIa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179C5BF26B74D9072D5B25031661CA76705A875322F6A50CBF3C4AF3E39E0AD2F639E07
sha3_384: 18cde69cdc73aa4750a1a2ad7ed61f72e0b9af6060fdcd46278ee4683845624b3b11428509c5aef2cf8383c4f19f4c78
ep_bytes: e8a2040000e980feffff558bec5156ff
timestamp: 2018-08-10 08:24:47

Version Info:

0: [No Data]

Mikey.120563 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebAdware.Softcnapp.92
FireEyeGeneric.mg.a56ea7cbc036a892
CAT-QuickHealTrojan.Skeeyah.S3293683
McAfeeSoftcnapp
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00535f0d1 )
K7GWAdware ( 00535f0d1 )
Cybereasonmalicious.ee66f3
CyrenW32/S-2a1c663c!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
Paloaltogeneric.ml
ClamAVWin.Malware.Softcnapp-6787524-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Mikey.120563
NANO-AntivirusTrojan.Win32.Softcnapp.fholbu
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Generic.e
SophosSoftcnapp (PUA)
ComodoApplication.Win32.AdWare.Softcnapp.O@80ok4p
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Softcnapp.vh
SentinelOneStatic AI – Malicious PE
EmsisoftApplication.Generic (A)
IkarusPUA.Softcnapp
GDataGen:Variant.Mikey.120563
JiangminTrojanDownloader.Adload.voc
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1142834
Antiy-AVLTrojan/Generic.ASMalwS.2771A65
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Helper.R233980
Acronissuspicious
VBA32BScope.Adware.Puwaders
MalwarebytesMalware.AI.3265076233
APEXMalicious
RisingAdware.Downloader!1.BBEC (CLASSIC)
YandexTrojan.GenAsa!VQgV47xo2Q4
eGambitUnsafe.AI_Score_99%
FortinetAdware/Softcnapp
AVGWin32:MalwareX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mikey.120563?

Mikey.120563 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment