Malware

Mikey.159335 removal instruction

Malware Removal

The Mikey.159335 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.159335 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mikey.159335?


File Info:

name: 865548C8ACEBE3064184.mlw
path: /opt/CAPEv2/storage/binaries/ba8cb6d50108028a9e27a3968e82120e283dc9b78eb30848b27144d72356e493
crc32: 1A02B0DE
md5: 865548c8acebe306418433c03bd75b2c
sha1: ddea48295a18f643fb3ecba80cc30ded2df58ea3
sha256: ba8cb6d50108028a9e27a3968e82120e283dc9b78eb30848b27144d72356e493
sha512: 3dbcb96bbe25e16646bcab1692699f081e54dd0be7b07607d497d80ee81aba54eb5a324af025131985a8c8054ccb90acbccc42c907c845498e27d9b90e200809
ssdeep: 24576:DSsFdmKBzH+I2LM4V3ISvD0zO3l4YwSPAn20p9KVODXnBWDh1Ri1ah9xGzXw6iwe:DlN273lRjRSqxcXPwEBYSd5TtwuXrW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17CC59E13F6D1C873E645013045B727357B75E7621F25DBA3A3A0FCB82E22251AA6B2CD
sha3_384: 6f226c94faa66b392c8a0ce7f2e17ec65f3681b5cc26801c43a2cb74c139398d4f0f1dfe57b81e2c9c4b0b4512691bab
ep_bytes: 558bec6aff6898a262006834fb520064
timestamp: 2013-04-12 12:28:07

Version Info:

FileVersion: 2.7.0.1
FileDescription: www.luokexf.com
ProductName: 洛克王国旋风辅助
ProductVersion: 2.7.0.1
CompanyName: 洛克王国旋风辅助
LegalCopyright: 洛克王国旋风辅助 官网:www.luokexf.com 邮箱:admin@luokexf.com
Comments: www.luokexf.com
Translation: 0x0804 0x04b0

Mikey.159335 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Mikey.159335
FireEyeGeneric.mg.865548c8acebe306
SkyhighBehavesLike.Win32.Generic.vh
ALYacGen:Variant.Mikey.159335
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Jorik.Win32.233382
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.95a18f
ArcabitTrojan.Mikey.D26E67
BaiduWin32.Trojan.Benban.a
VirITTrojan.Win32.Generic.CAVH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Injector.A potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Benban-9840578-0
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Mikey.159335
NANO-AntivirusTrojan.Win32.Benban.cxntwh
AvastWin32:Evo-gen [Trj]
TACHYONTrojan/W32.Jorik.2633728.C
EmsisoftGen:Variant.Mikey.159335 (B)
DrWebTrojan.Click2.50011
VIPREGen:Variant.Mikey.159335
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Benban
VaristW32/Trojan.CLL.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.999
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.gen
GDataWin32.Trojan.PSE.1FX883P
GoogleDetected
AhnLab-V3Trojan/Win.Benban.R623834
McAfeeGenericRXBN-XK!865548C8ACEB
MAXmalware (ai score=86)
VBA32Trojan.Click
Cylanceunsafe
PandaGeneric Malware
RisingTrojan.Win32.Generic.1470F098 (C64:YzY0Oq9Jk9kiI+kN)
YandexTrojan.GenAsa!bthzHOpCEx0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Kolovorot.in
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Mikey.159335?

Mikey.159335 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment