Worm

Should I remove “Worm:Win32/Moarider.A”?

Malware Removal

The Worm:Win32/Moarider.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Moarider.A virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself

How to determine Worm:Win32/Moarider.A?


File Info:

crc32: CDB424CC
md5: 491a70936e8b21920d2b183129b687e1
name: 491A70936E8B21920D2B183129B687E1.mlw
sha1: aa156f0fa32c98dacfb710595c2d0a68115cdbb2
sha256: 7cb4b3df2fb0058a2d8bd5ece903c1c3c6241f0e3b6e85d6c83454a795cde393
sha512: 05a9a2f42cbe66957f272798b783ccd0b0355afa422eadbff36502b3b22bc7e7d1af65c5fdfac41e63af2bc286a83417187ae6521cc3975b6b7f2bcf696afed9
ssdeep: 6144:kuIlWqB+ihabs7Ch9KwyF5LeLodp2D1Mmakda0qL4ks3ih1XGWS:P6Wq4aaE6KwyF5L0Y2D1PqLW3c2z
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Worm:Win32/Moarider.A also known as:

BkavW32.FamVT.TofseeMX.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.umNfrv@Sinlib
FireEyeGeneric.mg.491a70936e8b2192
CAT-QuickHealTrojan.AutoIt.Pistolar.A
McAfeeW32/Worm-FMA!491A70936E8B
CylanceUnsafe
ZillyaWorm.AutoitGen.Win32.1029
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Trojan.Heur.umNfrv@Sinlib
K7GWTrojan ( 700000111 )
Cybereasonmalicious.36e8b2
TrendMicroTROJ_GEN.R06EC0CKI20
BaiduWin32.Trojan.AutoIt.a
CyrenW32/AutoIt.RT.gen!Eldorado
SymantecW32.SillyFDC
APEXMalicious
AvastAutoIt:Agent-DP [Trj]
ClamAVWin.Malware.Autoit-6991628-0
KasperskyTrojan.Win32.Autoit.aza
NANO-AntivirusTrojan.Script.AutoIt.dbycya
Ad-AwareGen:Trojan.Heur.umNfrv@Sinlib
SophosMal/Sohana-A
ComodoTrojWare.Win32.Autoit.AZA@53pfkb
F-SecureTrojan.TR/AutoIt.axovq
DrWebTrojan.DownLoader6.18661
VIPREPacker.NSAnti.Gen (v)
InvinceaML/PE-A + Mal/Sohana-A
McAfee-GW-EditionBehavesLike.Win32.Worm.fc
EmsisoftGen:Trojan.Heur.umNfrv@Sinlib (B)
JiangminTrojan.Hesv.dnb
AviraTR/AutoIt.axovq
Antiy-AVLGrayWare/Autoit.Wacatac.a
MicrosoftWorm:Win32/Moarider.A
ArcabitTrojan.Heur.E19A9B
SUPERAntiSpywareTrojan.Agent/Gen-Autorun
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.umNfrv@Sinlib
CynetMalicious (score: 100)
AhnLab-V3HEUR/Fakon.mwf.X1381
Acronissuspicious
BitDefenderThetaAI:Packer.9EEF58351D
VBA32Trojan.Autoit.Wirus
MalwarebytesWorm.Agent.GT
ZonerTrojan.Win32.Autoit.32800
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R06EC0CKI20
RisingMalware.FakeFolder@CV!1.6AA9 (CLASSIC)
MAXmalware (ai score=81)
eGambitUnsafe.AI_Score_51%
FortinetW32/Autoit.NLQ!tr
AVGAutoIt:Agent-DP [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.5DB7.Malware.Gen

How to remove Worm:Win32/Moarider.A?

Worm:Win32/Moarider.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment