Malware

Mikey.134079 removal

Malware Removal

The Mikey.134079 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.134079 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Macedonian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Mikey.134079?


File Info:

name: E9F481175176DA4C304C.mlw
path: /opt/CAPEv2/storage/binaries/89fddb8aef7029f6f06c4109aa0548e5ab16c2f41245a94c55444927271237b1
crc32: 6166E1CE
md5: e9f481175176da4c304c56113335db15
sha1: d88e528b7ab3ac665319b98f83f2ba4345d30d5c
sha256: 89fddb8aef7029f6f06c4109aa0548e5ab16c2f41245a94c55444927271237b1
sha512: 0fa2a2c20cb27b174f87aff4115b53f5d9590e32409d48cd82bf882fde58eaf1bfc9a887dc36b91cd0d0dbaa5e131bf7ee3bbb1bb9e1769fbd1c9a52464d7f53
ssdeep: 6144:poavqpxz4NcfsMbFMr5UNpwsMCjGzcrgzcrgzcrgzcrgzcrgzcrgzcrgzcrgzcrn:+WmxcO0DrmpM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12EB6C74266E1DC16F6F30A74593542D92A77FCE6A825864FF0643F1B38B22C26DB0763
sha3_384: 8ab2f8e8e370a95fa0f1604e719e5ff53073956f6b863221edab8b0ae06689428f3cc1161697a6019163910df59ed5ea
ep_bytes: e8b2640000e978feffffcccccccccccc
timestamp: 2020-10-04 07:13:34

Version Info:

FileVers: 65.51.36.16
ProductVersa: 7.50.25.71
InternalName: peatemas
LegalCopyrighd: sharnir
Translation: 0x0169 0x0300

Mikey.134079 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.38134
MicroWorld-eScanGen:Variant.Mikey.134079
FireEyeGeneric.mg.e9f481175176da4c
McAfeePacked-GBE!E9F481175176
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3685821
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058d8e41 )
K7GWTrojan ( 0058d8e41 )
Cybereasonmalicious.b7ab3a
BitDefenderThetaGen:NN.ZexaF.34182.@t0@aekpDPkG
CyrenW32/Kryptik.FXB.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HODO
ClamAVWin.Packed.Crypterx-9936080-0
KasperskyHEUR:Backdoor.Win32.Tofsee.pef
BitDefenderGen:Variant.Mikey.134079
AvastWin32:DropperX-gen [Drp]
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Xiquitir.vm
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.351A455
MicrosoftTrojan:Win32/Raccrypt.GE!MTB
GDataGen:Variant.Mikey.134079
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Stop.R468728
VBA32Malware-Cryptor.2LA.gen
ALYacGen:Variant.Mikey.134079
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingBackdoor.Tofsee!8.1E9 (RDMK:cmRtazoifv1ZJW4mBTYHAeKSGuuN)
YandexTrojan.Kryptik!l6v1gWKnS8k
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.FQFH!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Mikey.134079?

Mikey.134079 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment