Malware

Mikey.126924 removal instruction

Malware Removal

The Mikey.126924 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.126924 virus can do?

  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time

Related domains:

2398.35go.net
infoc0.duba.net
config.i.duba.net

How to determine Mikey.126924?


File Info:

crc32: 4563B25D
md5: b1dfdbdf20e8a9f617c17a3238cd684e
name: B1DFDBDF20E8A9F617C17A3238CD684E.mlw
sha1: 648d97cd5747217e866779d6bcac9bdfee5dcfbb
sha256: e54a390bd42a0e477f8253863f0789d809afbea2aecfd9ee83949383091a8af6
sha512: 6116f7b09f920ae9e2ba8442c4bc37ea7cc5514a80239dad4fb94ff03243bb25acf768dfcdc6c92c8a0d46360885dbaae5224483824095de5bbf1e1afe653f99
ssdeep: 24576:VV7SnHZSgWAHlGHDqQif/nDPkaEL6xVgJ2f5LXVB4C78f76+CyMAO0eQiUMB80eC:D7yHQgWAFGHDqZMhLKz5bVBtmm+xMbyG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998-2021 Kingsoft Corporation
InternalName: KInstallTool
FileVersion: 2021,08,25,954
CompanyName: Kingsoft Corporation
ProductName: Kingsoft Internet Security
ProductVersion: 9,3,0,954
FileDescription: Kingsoft Security - x5b89x88c5x7a0bx5e8f
OriginalFilename:
Translation: 0x0000 0x04b0

Mikey.126924 also known as:

K7AntiVirusUnwanted-Program ( 00560ccc1 )
LionicRiskware.Win32.Mikey.1!c
ALYacGen:Variant.Mikey.126924
BitDefenderGen:Variant.Mikey.126924
K7GWUnwanted-Program ( 00560ccc1 )
CyrenW32/KingSoft.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KingSoft.L potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
MicroWorld-eScanGen:Variant.Mikey.126924
Ad-AwareGen:Variant.Mikey.126924
SophosGeneric PUA GE (PUA)
McAfee-GW-EditionBehavesLike.Win32.Worm.tc
FireEyeGen:Variant.Mikey.126924
EmsisoftGen:Variant.Mikey.126924 (B)
JiangminBackdoor.Generic.btxp
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Mikey.126924
AhnLab-V3Malware/Win.Generic.C4611220
McAfeeGenericRXAA-AA!B1DFDBDF20E8
MAXmalware (ai score=85)
VBA32BScope.Trojan.Bugor
FortinetW32/Fragtor.8085!tr

How to remove Mikey.126924?

Mikey.126924 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment