Malware

Ser.Mikey.2382 malicious file

Malware Removal

The Ser.Mikey.2382 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Mikey.2382 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Marathi
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Ser.Mikey.2382?


File Info:

name: E1C33CBBD4D889280E1B.mlw
path: /opt/CAPEv2/storage/binaries/4f75afe0e4d254de3e63c47e52914d602778a5265718f7dbb1f62e315e0482b0
crc32: CF1EF3EE
md5: e1c33cbbd4d889280e1bc1b951547654
sha1: 17d4497738bd6eae587a930a81d6a6c628dcc06b
sha256: 4f75afe0e4d254de3e63c47e52914d602778a5265718f7dbb1f62e315e0482b0
sha512: 25f3853e0a45be4c0b3f0ae1708369596e62181a269b23021c091c7738eb29288afb26e8759d4a450fbc7d02b810b7752f57c1a20cd035d913f7b678b8a4eb57
ssdeep: 1536:rJRBn9648yajemgzXIltMLmcn8AmP6dVVntCTcOIrsy3Z8aLMa66QJtbdV9DQznx:rPBEeZclGLlz7NtwIoypt6HJtbdTQU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E734AD12B6A0D431C59F4A34487493A11B7ABC52577508BFB7643B2F2EB02D11EB939F
sha3_384: 767af50668c0d125287d1d9ca57a008506113c28a18406a0129bd700980fb4d1472ef973c3b04ee4a54e60df4ecb2811
ep_bytes: e861260000e989feffff6a0aff159810
timestamp: 2021-06-08 07:33:35

Version Info:

FileVersion: 49.46.71.23
Copyrighz: Copyright (C) 2022, pozkarte
ProjectVersion: 28.81.74.73

Ser.Mikey.2382 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader44.58472
MicroWorld-eScanGen:Variant.Ser.Mikey.2382
FireEyeGeneric.mg.e1c33cbbd4d88928
ALYacGen:Variant.Jaik.71493
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005923e21 )
K7GWTrojan ( 005923e21 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.GNB.gen!Eldorado
SymantecPacked.Generic.525
tehtrisGeneric.Malware
ESET-NOD32Win32/Smokeloader.F
ClamAVWin.Malware.Filerepmalware-9941437-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Ser.Mikey.2382
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Ser.Mikey.2382
EmsisoftGen:Variant.Ser.Mikey.2382 (B)
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dt
SophosMal/Generic-S
IkarusTrojan-Ransom.StopCrypt
AviraTR/SmokeLoader.lnuzd
MAXmalware (ai score=88)
MicrosoftRansom:Win32/StopCrypt.PBO!MTB
GDataGen:Variant.Ser.Mikey.2382
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win.BeamWinHTTP.R490743
Acronissuspicious
McAfeeGenericRXSV-JO!E1C33CBBD4D8
VBA32BScope.Trojan.LokiBot
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgVsYsBtWTkVqw)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HPLT!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.738bd6
PandaTrj/GdSda.A

How to remove Ser.Mikey.2382?

Ser.Mikey.2382 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment