Worm

Worm:Win32/Mira information

Malware Removal

The Worm:Win32/Mira is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mira virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to execute a powershell command with suspicious parameter/s
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Worm:Win32/Mira?


File Info:

crc32: D7936B11
md5: 55aab24b7fd1ecfc3652db2cc14dd67d
name: 55AAB24B7FD1ECFC3652DB2CC14DD67D.mlw
sha1: 0e1b5167510b66ddea58680de98ccfecdc5434df
sha256: 9b5757f9cd56b69c323397c1d0d368441e27d7a9b192aa7f44956233328b07ca
sha512: a95e5c710d41864c48f5bc394c62b0aa6bceec4b3af2adfcd9522cb46ea9b3e5f87a3dfc0c680d4518c6044df954424deaa779ead1736ca10622d06c66ff465c
ssdeep: 12288:8kZJLuMkG579NJdn0cYOGxoWMan/4/Js7DAhC:zZHHhhdn0cEh4/JwaC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Mira also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004fdf181 )
CynetMalicious (score: 100)
ALYacDropped:Trojan.GenericKDZ.69837
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.33802
SangforTrojan.Generic-Script.Save.7b7a01dd
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.a498e2f0
K7GWTrojan ( 004fdf181 )
Cybereasonmalicious.b7fd1e
CyrenPSH/Dropper.A
SymantecML.Attribute.HighConfidence
ESET-NOD32PowerShell/TrojanDropper.Agent.D
APEXMalicious
AvastNSIS:Downloader-ACW [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.ifpe
BitDefenderDropped:Trojan.GenericKDZ.69837
MicroWorld-eScanDropped:Trojan.GenericKDZ.69837
TencentWin32.Trojan.Blocker.Swle
Ad-AwareDropped:Trojan.GenericKDZ.69837
SophosMal/Generic-S
ComodoTrojWare.Script.TrojanDropper.Agent.D@7l67fr
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Blocker.R002C0GKB20
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
FireEyeGeneric.mg.55aab24b7fd1ecfc
EmsisoftDropped:Trojan.GenericKDZ.69837 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1116910
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftWorm:Win32/Mira
AegisLabTrojan.Win32.Blocker.j!c
GDataPowerShell.Trojan-Dropper.Agent.AIT
AhnLab-V3Trojan/Win32.Agent.R348735
McAfeeArtemis!55AAB24B7FD1
MAXmalware (ai score=83)
VBA32Trojan-Ransom.Blocker
MalwarebytesAllaple.Worm.DDoS.DDS
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Blocker.R002C0GKB20
RisingWorm.Allaple/VBS!1.BD75 (CLASSIC)
IkarusWorm.Win32.Mira
FortinetVBS/PowerShell.D!tr
AVGNSIS:Downloader-ACW [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HoMASOkA

How to remove Worm:Win32/Mira?

Worm:Win32/Mira removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment