Malware

What is “Mikey.155211”?

Malware Removal

The Mikey.155211 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.155211 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mikey.155211?


File Info:

name: 82E8A76DADD86507B823.mlw
path: /opt/CAPEv2/storage/binaries/6f6166da2761adac444e5bcb8d8dc905f0aa03828a6d80f0f0775b3ebdbcac12
crc32: 5CA6F387
md5: 82e8a76dadd86507b8231e850b05020a
sha1: e0d95cd68ce4e978755356e1040bc6b559c962fb
sha256: 6f6166da2761adac444e5bcb8d8dc905f0aa03828a6d80f0f0775b3ebdbcac12
sha512: 960b9339660a268b2ce30a8c2d5171d6a14d670caf6f895b46898321775cbafeb7c44715310e81a1fc3bba1a4d0dfe252d5cf6ab86d54e0e7bf4db9639f27ec7
ssdeep: 24576:aR7+ptoodQmwkdsJmnsetIKsFLnpMklYAz:aR7+p/KXYAz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10035BF01B7C241F2D7042A300AE6677AFA799F591F16DFC397A4ED3C6C325409A361BA
sha3_384: 8a48dc374f99ab90607325528c3e94c0267f9952b5bedb5fb1dc46d5c8441e506af1a3aa4493f26e076ad06a4e44cfcb
ep_bytes: 558bec6aff68e0e34d0068b438460064
timestamp: 2013-03-20 11:51:33

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Mikey.155211 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mikey.155211
FireEyeGeneric.mg.82e8a76dadd86507
CAT-QuickHealDownloader.AdLoad.12395
SkyhighBehavesLike.Win32.Generic.th
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusTrojan ( 00539b2c1 )
K7GWTrojan ( 00539b2c1 )
Cybereasonmalicious.68ce4e
ArcabitTrojan.Mikey.D25E4B
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-583204
BitDefenderGen:Variant.Mikey.155211
EmsisoftApplication.Generic (A)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Mikey.155211
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusPUA.MSIL.Riskware
VaristW32/Trojan.GRW.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftProgram:Win32/Wacapew.C!ml
GDataWin32.Trojan.PSE.13YMLT9
GoogleDetected
AhnLab-V3Trojan/Win32.QQPass.C120953
ALYacGen:Variant.Mikey.155211
MAXmalware (ai score=88)
Cylanceunsafe
RisingStealer.QQPass!1.648F (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Mikey.155211?

Mikey.155211 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment