Malware

Should I remove “Mikey.50985”?

Malware Removal

The Mikey.50985 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.50985 virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Mikey.50985?


File Info:

name: 668ECEF9EBA5C2DA0470.mlw
path: /opt/CAPEv2/storage/binaries/b74bf1a9daf6110469a58f18c13a6fc2e37ef6668633ee0d957d4ca10f7e7113
crc32: 4AB08621
md5: 668ecef9eba5c2da0470994be48e2d50
sha1: 5ecd5da08ed5e3cad2374d890a9e95b42d067421
sha256: b74bf1a9daf6110469a58f18c13a6fc2e37ef6668633ee0d957d4ca10f7e7113
sha512: 880273b50c27581c0c88a0a09013bf320d59b1a075506088c00169a5378ece89e00f5143fdbfdc5892562f5904b0147922e80993bd56b3b0cdca8c187468c435
ssdeep: 6144:U4FfZ6zTwhmjsO4XcQ1F9lXYSbEcWcWcWc3:FFfZFhmoFZ1F9lXpIRRRW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B514F11836630077C89605B440D78E91377E69432FB74D1BAB9C6A4FAEF13C65AFA360
sha3_384: 1910a2227cae31b76e471d9ed0d7c1c99728e777f56414200143f7531b607e501bd5200b803cacfe0ac90abcb9a28a5f
ep_bytes: e839350000e917feffff8b44240433c9
timestamp: 2015-03-19 06:37:46

Version Info:

0: [No Data]

Mikey.50985 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Androm.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mikey.50985
FireEyeGeneric.mg.668ecef9eba5c2da
CAT-QuickHealRansom.TeslaCrypt.A3
McAfeeGeneric BackDoor.dl
MalwarebytesMalware.Heuristic.1004
ZillyaBackdoor.Androm.Win32.17004
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3ef1 )
AlibabaRansom:Win32/Tescrypt.f7013712
K7GWTrojan ( 0055e3ef1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36350.mmW@autpsXmi
VirITTrojan.Win32.Cryptlocker.AK
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.TeslaCrypt.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Androm.gmfv
BitDefenderGen:Variant.Mikey.50985
NANO-AntivirusTrojan.Win32.Androm.dphiaa
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
AvastWin32:GenMalicious-LGB [Trj]
TencentMalware.Win32.Gencirc.11538032
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.zmklz
DrWebTrojan.AVKill.36498
VIPREGen:Variant.Mikey.50985
TrendMicroTROJ_CRYPCTB.YVN
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Mikey.50985 (B)
IkarusTrojan.Win32.Filecoder
GDataGen:Variant.Mikey.50985
JiangminBackdoor/Androm.gpz
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.XPACK.zmklz
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Androm
XcitiumMalware@#3rujxmeufcyzo
ArcabitTrojan.Mikey.DC729
ZoneAlarmBackdoor.Win32.Androm.gmfv
MicrosoftRansom:Win32/Tescrypt.A
AhnLab-V3Trojan/Win32.Tescrypt.C762771
Acronissuspicious
ALYacGen:Variant.Mikey.50985
TACHYONBackdoor/W32.Androm.200704.AA
VBA32BScope.TrojanRansom.Tescrypt
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_CRYPCTB.YVN
RisingRansom.Tescrypt!8.3AF (TFE:5:kI9zwTtvNTK)
YandexTrojan.GenAsa!QIlJVdQ692U
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.EM!tr
AVGWin32:GenMalicious-LGB [Trj]
Cybereasonmalicious.9eba5c
DeepInstinctMALICIOUS

How to remove Mikey.50985?

Mikey.50985 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment