Malware

What is “Mikey.136701”?

Malware Removal

The Mikey.136701 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.136701 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Mikey.136701?


File Info:

name: 30F19042056C27A141B8.mlw
path: /opt/CAPEv2/storage/binaries/c688f17ed6e092d6203ff21194a08d972bf5939d89d603d80faadff72d66ddac
crc32: C0E4CB60
md5: 30f19042056c27a141b83acad6619d8d
sha1: 328feaff989ac6a7fd02176801dbbf62552f5d12
sha256: c688f17ed6e092d6203ff21194a08d972bf5939d89d603d80faadff72d66ddac
sha512: 3b51135d92700c029c4c2a8f9740b777543506e728125e6585322bd4a017eb7412a70563171dbd2aa85da2a6c31eae8eaed9f88f2d5264cf85ddcc885c5d50c3
ssdeep: 3072:8jH0idM7zV3ctmZfHRuEIwBhFdCNbf7DVox:QUuM7zVstmdAwBcNbfnV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED04CF1075E0F436D46389346870D6A27E7BBC229A74849B2B98276E2F701C39FF5367
sha3_384: e7e850a8768caa9bf5faa495b428bde37d291f931c334bec579998d186478a87edf78fd8c1b6695df910d845399ac182
ep_bytes: e8ef1d0000e989feffff8bff558bec83
timestamp: 2021-09-23 20:30:16

Version Info:

FileVersion: 8.71.86.86
Copyrighz: Copyright (C) 2022, pazkarte
ProjectVersion: 28.81.74.73

Mikey.136701 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mikey.136701
FireEyeGeneric.mg.30f19042056c27a1
McAfeePacked-GEE!30F19042056C
K7AntiVirusTrojan ( 00591df31 )
K7GWTrojan ( 00591df31 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Mikey.D215FD
CyrenW32/Kryptik.GKN.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HPHV
APEXMalicious
CynetMalicious (score: 99)
KasperskyVHO:Trojan-Ransom.Win32.Stop.gen
BitDefenderGen:Variant.Mikey.136701
AvastWin32:AceCrypter-U [Cryp]
Ad-AwareGen:Variant.Mikey.136701
EmsisoftTrojan.Crypt (A)
McAfee-GW-EditionPacked-GEE!30F19042056C
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.Agent.kacla
MAXmalware (ai score=84)
MicrosoftRansom:Win32/StopCrypt.PBJ!MTB
GDataGen:Variant.Mikey.136701
AhnLab-V3Infostealer/Win.SmokeLoader.R487069
ALYacGen:Variant.Mikey.136701
MalwarebytesTrojan.MalPack.GS
RisingRansom.Stop!8.10810 (TFE:dGZlOgUtLeQE66KF8A)
IkarusTrojan.ArkeiStealer
FortinetW32/Kryptik.HPGE!tr
AVGWin32:AceCrypter-U [Cryp]
PandaTrj/GdSda.A

How to remove Mikey.136701?

Mikey.136701 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment