Malware

Mikey.139659 removal

Malware Removal

The Mikey.139659 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.139659 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • CAPE detected the Sakula malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mikey.139659?


File Info:

name: 351D527327E60E411178.mlw
path: /opt/CAPEv2/storage/binaries/9413f2e40ffec65e09a2be5e5777babbd386d09c5eaf9c3b57b2919186696f5f
crc32: 425CDDA6
md5: 351d527327e60e4111787eea7d67e73e
sha1: 97c91f2c8b30a766a152eb6e1d81320c517e9690
sha256: 9413f2e40ffec65e09a2be5e5777babbd386d09c5eaf9c3b57b2919186696f5f
sha512: 183cdbf23c3ee8363e94b32173c1d355d23e3338dcc310f43193df8395229d150934b765aa7cc15dd359d818eefd8b744db1196573b2bb0292c2c7f0b56aa93f
ssdeep: 6144:kdgv30si81H+Uyc4WLrxBcQtz8Q0bDC3zUonh8CD2Kc+hG:x71HTyc4WnxBF8Q02UonhsF+hG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150A47D13F1808132E166293005A19B7496FF7EE46A38F36F6E5C767B2F732C2652531A
sha3_384: f4564379cc096b1e080fb9ba185287319add10360b59e3a2f26853e1ac5b2cabaad763f5952d653ea1176d239fd7ee7e
ep_bytes: e894470000e979feffff3b0d00de4200
timestamp: 2014-05-23 08:07:49

Version Info:

CompanyName: Juniper Networks , Inc
FileDescription: Juniper SSL VPN ActiveX Plugin.
FileVersion: 1, 3, 2, 1
InternalName: Juniper SSL VPN ActiveX.exe
LegalCopyright: Juniper Networks , Inc. All rights reserved.
OriginalFilename: Juniper SSL VPN ActiveX.exe
ProductName: Juniper SSL VPN ActiveX
ProductVersion: 1, 3, 2, 1
Translation: 0x0409 0x04e4

Mikey.139659 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mivast.4!c
MicroWorld-eScanGen:Variant.Mikey.139659
McAfeeRDN/Generic BackDoor
MalwarebytesAgent.Trojan.Clicker.DDS
VIPREGen:Variant.Mikey.139659
SangforBackdoor.Win32.Mivast.Vydt
K7AntiVirusTrojan ( 004eb99a1 )
AlibabaBackdoor:Win32/Mivast.97f085cc
K7GWTrojan ( 004eb99a1 )
CyrenW32/ABRisk.RANZ-5961
SymantecBackdoor.Mivast
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Shyape.L.gen
APEXMalicious
KasperskyBackdoor.Win32.Mivast.a
BitDefenderGen:Variant.Mikey.139659
NANO-AntivirusTrojan.Win32.Mivast.duzkif
AvastWin32:Derusbi-L [Trj]
TencentMalware.Win32.Gencirc.115d9681
EmsisoftGen:Variant.Mikey.139659 (B)
F-SecureTrojan.TR/Drop.Agent.449352
DrWebBackDoor.Tdss.10911
ZillyaBackdoor.Mivast.Win32.7
TrendMicroTROJ_GEN.R002C0PF423
McAfee-GW-EditionRDN/Generic BackDoor
Trapminesuspicious.low.ml.score
FireEyeGen:Variant.Mikey.139659
SophosMal/Generic-S
IkarusTrojan.Win32.Turla
GDataGen:Variant.Mikey.139659
JiangminBackdoor/Mivast.a
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Drop.Agent.449352
Antiy-AVLTrojan/Win32.Shyape
ArcabitTrojan.Mikey.D2218B
ViRobotTrojan.Win32.Sakula.449352
ZoneAlarmBackdoor.Win32.Mivast.a
MicrosoftBackdoor:Win32/Plugx.N!dha
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Sakelua.C932363
ALYacGen:Variant.Mikey.139659
MAXmalware (ai score=100)
VBA32Backdoor.Mivast
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PF423
RisingBackdoor.Mivast!8.4AD4 (TFE:5:fNL3rv8TntU)
YandexBackdoor.Mivast!q/GTk6p9MUo
MaxSecureSpy.W32.Agent.dffz_274403
FortinetW32/PossibleThreat
AVGWin32:Derusbi-L [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mikey.139659?

Mikey.139659 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment