Malware

Should I remove “ELF:Mirai-ATL [Trj]”?

Malware Removal

The ELF:Mirai-ATL [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ELF:Mirai-ATL [Trj] virus can do?

  • At least one process apparently crashed during execution
  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine ELF:Mirai-ATL [Trj]?


File Info:

crc32: F0586829
md5: c85e423e0b5c75d7a9516acf700e8e18
name: tmp_6rq2rbs
sha1: 749a125ddd1433db77edfcec49e25351dd302850
sha256: 7501fe9ee5dc3e58a98d34dfb2906ce8e8e739be4805cb495b28107f2ed26978
sha512: ff963bd203a6f9a72aa6cf38be45e437b44ae4a649125cea6499e991498093324bf141ae0525975318b3598a09f85ab1720dcd883a8aa65b08a3d9326821cce8
ssdeep: 1536:Oa8tF/MUQ75ifwt1ARSAmJF/Naz/TlHmrmCwM:OXttMUQ75QQbOTlmrm
type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped

Version Info:

0: [No Data]

ELF:Mirai-ATL [Trj] also known as:

ClamAVUnix.Dropper.Mirai-7135890-0
FireEyeTrojan.Linux.Mirai.1
McAfeeLinux/Mirai.g
SangforMalware
SymantecTrojan.Gen.NPE
TrendMicro-HouseCallTrojan.Linux.MIRAI.SMMR1
AvastELF:Mirai-ATL [Trj]
CynetMalicious (score: 85)
GDataLinux.Trojan.Mirai.J
KasperskyHEUR:Backdoor.Linux.Mirai.ba
BitDefenderTrojan.Linux.Mirai.1
MicroWorld-eScanTrojan.Linux.Mirai.1
RisingBackdoor.Mirai/Linux!1.BAF6 (CLASSIC)
Ad-AwareTrojan.Linux.Mirai.1
EmsisoftTrojan.Linux.Mirai.1 (B)
ComodoMalware@#1svs56kzfsggs
DrWebLinux.Mirai.4350
TrendMicroTrojan.Linux.MIRAI.SMMR1
McAfee-GW-EditionLinux/Mirai.g
SophosLinux/DDoS-CIA
IkarusTrojan.Linux.Mirai
CyrenELF/Mirai.D.gen!Camelot
JiangminBackdoor.Linux.dwvb
AviraLINUX/Mirai.kikcu
Antiy-AVLTrojan[Backdoor]/Linux.Mirai.ba
MicrosoftDDoS:Linux/Gafgyt.YA!MTB
ArcabitTrojan.Linux.Mirai.1
ZoneAlarmHEUR:Backdoor.Linux.Mirai.ba
Avast-MobileELF:Mirai-UM [Trj]
AhnLab-V3Linux/Mirai.Gen3
BitDefenderThetaGen:NN.Mirai.34128
ALYacTrojan.Linux.Mirai.1
ESET-NOD32a variant of Linux/Mirai.AT
TencentBackdoor.Linux.Mirai.wbc
MAXmalware (ai score=100)
FortinetELF/Mirai.AT!tr
AVGELF:Mirai-ATL [Trj]

How to remove ELF:Mirai-ATL [Trj]?

ELF:Mirai-ATL [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment