Worm

Worm:Win32/Mira!rfn removal tips

Malware Removal

The Worm:Win32/Mira!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mira!rfn virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Worm:Win32/Mira!rfn?


File Info:

crc32: 8F62D6BC
md5: 6536d868b2bb410ba8d1a6a4eb62d401
name: 6536D868B2BB410BA8D1A6A4EB62D401.mlw
sha1: f30721b3658c23a5b63aff35547b307f1f38dcb4
sha256: 97fde0c9d09bae1b392d4a36fff6e5042eae9bd0e9184ef876b569d7cfda77c1
sha512: b9c78a8112fbedc29f7dd97eaf105232e9dd0fd35aa2c9a40b404c8a85032d3f09b2bb92545e575f4a3077b7632cbffd92e81cdf41c4d4367c5ea08b155af472
ssdeep: 12288:P1/aGLDCMNpNAkoSzZWD8ayX2MQCw7D0avKpC0bHOVW29SdrYwI76yn:P1/aGLDCM4D8ayGMOKbHOb6Yf76yn
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Mira!rfn also known as:

BkavW32.FamVT.MiraVM.Worm
DrWebWin32.HLLO.Siggen.5
MicroWorld-eScanTrojan.GenericKD.32372893
CAT-QuickHealTrojan.GenericPMF.S7683580
ALYacTrojan.GenericKD.32372893
CylanceUnsafe
ZillyaTrojan.Agent.Win32.530055
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/Dorpal.ali1000029
K7GWTrojan ( 004993691 )
K7AntiVirusTrojan ( 004993691 )
TrendMicroWORM_MIRAS.SMN
BaiduWin32.Worm.Mira.c
CyrenW32/S-7e474b30!Eldorado
ESET-NOD32Win32/Mira.A
APEXMalicious
TotalDefenseWin32/Tnega.MFcdAFD
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-1388690
GDataWin32.Worm.Mira.D
KasperskyTrojan.Win32.Agent.icgh
BitDefenderTrojan.GenericKD.32372893
NANO-AntivirusTrojan.Win32.Zusy.ethqlz
TencentWorm.Win32.Mira.a
Ad-AwareTrojan.GenericKD.32372893
SophosW32/Mira-B
ComodoWorm.Win32.Mira.AA@59ticr
F-SecureTrojan.TR/Zusy.BQ
BitDefenderThetaGen:NN.ZexaF.34110.RCZ@aiiPd4ci
VIPREWorm.Win32.Mira.a (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Worm.jc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.6536d868b2bb410b
EmsisoftTrojan.GenericKD.32372893 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/S-7e474b30!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Gen.Bt
AviraTR/Zusy.BQ
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Agent.icgh
MicrosoftWorm:Win32/Mira!rfn
JiangminTrojan/Agent.iezf
ArcabitTrojan.Generic.D1EDF89D
AegisLabTrojan.Win32.Agent.lY1Q
ZoneAlarmTrojan.Win32.Agent.icgh
AhnLab-V3Trojan/Win32.Fakon.R291518
Acronissuspicious
McAfeeW32/Worm-GAT!6536D868B2BB
MAXmalware (ai score=88)
VBA32Trojan.Agent
MalwarebytesWorm.Mira
PandaW32/Milam.A.worm
TrendMicro-HouseCallWORM_MIRAS.SMN
RisingWorm.Mira!1.A270 (CLOUD)
YandexTrojan.Agent!OS9hDvN2kyI
IkarusTrojan.Minggy
MaxSecureTrojan.Agent.icgh
FortinetW32/Mira.9C5!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Worm.Win32.Mira.A

How to remove Worm:Win32/Mira!rfn?

Worm:Win32/Mira!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment