Malware

Mikey.135692 (file analysis)

Malware Removal

The Mikey.135692 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.135692 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Mikey.135692?


File Info:

name: 3F3AAA9A3103B74A6AA0.mlw
path: /opt/CAPEv2/storage/binaries/bcf10fd2a15fafcb48858491b40e9cf0f52de991d30fcf3f999a567fe6524bcd
crc32: 7BB041C0
md5: 3f3aaa9a3103b74a6aa03d81c22402f7
sha1: 7964adbcfdd33c0a413bb108750f7985d5419362
sha256: bcf10fd2a15fafcb48858491b40e9cf0f52de991d30fcf3f999a567fe6524bcd
sha512: 0c4bb3e80e7cf6ef214299e8aee9b1090e3a55b4d52e4bfaef7d7252588d2ebf08b1942f93b52474aabe812fcea691a7d29639da8ed876f02a86466960eb3b1b
ssdeep: 98304:I4fecfUF+gGPpL5SbWf+YFCbu/ySxMXxJTAYULMJ+o:I2fUAPpQaf+HmyXcT8+o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18E56CF23E24180B1E9191A70257713397A349F695935CA83F7ECFD76BF32262972720E
sha3_384: bc67ae74b1f86adcef9a7ade085f59dbb217810250d1290615b3e553ac16f383c7fb11030fe479017a07cd543d27fd38
ep_bytes: 558bec6aff68e069970068ec57550064
timestamp: 2022-07-29 12:46:26

Version Info:

FileVersion: 9.6.2.28756
FileDescription: 腾讯QQ
ProductName: 腾讯QQ
ProductVersion: 9.6.2.28756
CompanyName: Tencent
LegalCopyright: Copyright (C) 1999-2020 Tencent. All Rights Reserved
Comments: Tencent
Translation: 0x0804 0x04b0

Mikey.135692 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Mikey.135692
CAT-QuickHealRisktool.Flystudio.17329
ALYacGen:Variant.Mikey.135692
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
Cybereasonmalicious.a3103b
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Injector.D potentially unwanted
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
BitDefenderGen:Variant.Mikey.135692
Ad-AwareGen:Variant.Mikey.135692
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Mikey.135692
McAfee-GW-EditionBehavesLike.Win32.BadFile.th
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.3f3aaa9a3103b74a
EmsisoftGen:Variant.Mikey.135692 (B)
GDataWin32.Trojan.PSE.1DNV50E
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Mikey.D2120C
MicrosoftTrojan:Win32/Sabsik.EN.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!3F3AAA9A3103
VBA32BScope.Trojan.BtcMine
MalwarebytesTrojan.MalPack.FlyStudio
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
BitDefenderThetaGen:NN.ZexaE.34806.@t0@aydcV!iH

How to remove Mikey.135692?

Mikey.135692 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment