Malware

Mikey.95481 (B) removal instruction

Malware Removal

The Mikey.95481 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.95481 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

www.baidu.com
w.timyy.com

How to determine Mikey.95481 (B)?


File Info:

crc32: 5A0FDCCF
md5: c8043b241df8c11a0da9aa95cff95fcc
name: C8043B241DF8C11A0DA9AA95CFF95FCC.mlw
sha1: 5ef2735d10d87dcde62e70bfa78b7ba5d3cb4311
sha256: 7a34777b0818c41336e3fd503241e1ed38dd6bbd94f742cbe3a6d5800306e26f
sha512: 81df73a072d7882380fb91e5cbd7934fdcb3bb749e7e2f99dd0addf83121099bb34257763b56b3397737e0e250b22c53ab234a3f96a210a05692c633c9fcc23a
ssdeep: 12288:vGp5LRNtAAxG2/O92gJXM5luvYZ8w2ilHB+m8zvd2R5nWFpPoSfLN:vGZcAxR/U2QXOlY2GzFtbJB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Qx7fa4 60897370 x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: Qx7fa4 60897370
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x82b1x56edx5de5x5177
ProductVersion: 1.0.0.0
FileDescription: Qx7fa4 60897370
Translation: 0x0804 0x04b0

Mikey.95481 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mikey.95481
FireEyeGeneric.mg.c8043b241df8c11a
CAT-QuickHealRisktool.Flystudio.16884
ALYacGen:Variant.Mikey.95481
CylanceUnsafe
SangforWin.Malware.Zusy-6840460-0
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Mikey.95481
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.41df8c
BitDefenderThetaGen:NN.ZexaF.34590.9q0@aaAPxVkb
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Zusy-6840460-0
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazrc8VZENcjOseIKPhAdBo1F)
Ad-AwareGen:Variant.Mikey.95481
EmsisoftGen:Variant.Mikey.95481 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosGeneric ML PUA (PUA)
IkarusTrojan.Black
JiangminTrojanDownloader.Agent.cwql
MaxSecureDropper.Dinwod.frindll
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftTrojanDownloader:Win32/Emotet!ml
ArcabitTrojan.Mikey.D174F9
GDataWin32.Trojan.PSE.1FOH0JX
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!C8043B241DF8
MAXmalware (ai score=88)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
YandexTrojan.GenAsa!iU7Jf6XNfF0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.65CA!tr
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Ransom.WannaCry.HgIASPkA

How to remove Mikey.95481 (B)?

Mikey.95481 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment