Worm

Worm:Win32/Moarider!pz removal tips

Malware Removal

The Worm:Win32/Moarider!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Moarider!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Worm:Win32/Moarider!pz?


File Info:

name: A2C990FD8A5C0024AB23.mlw
path: /opt/CAPEv2/storage/binaries/7b62a78a80cf451bba6bfc40a12fafd6cf08856c0b723edfe622b9f0e4b9c307
crc32: A70D79AC
md5: a2c990fd8a5c0024ab231cf7d9035869
sha1: 485881d85ed8d325ef51753c42a3bb8554236284
sha256: 7b62a78a80cf451bba6bfc40a12fafd6cf08856c0b723edfe622b9f0e4b9c307
sha512: bf4eca557ff7916d05eabb86b29368053659eb5ab64aa88255c4d638a8526d9132a267acc9ddf85401bea57a80a3f429cd4f4cfe2cdcfafb984cb73c1e931c24
ssdeep: 3072:e630thKdTAodJza64TRnltulOuQuT1XwQVXz5u01OGsLo3XEqfX:e0ZETpYzA2LsLc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F354F603B3EA945ED8B277B05EFAD355C637BD299233C21F3284195F5DA1A405E223B2
sha3_384: 931023dd55e127e60f5c0b8ead12b893255ceaa4deb3b650108b855475acafe03aa3c199247067db171f053ad658683c
ep_bytes: 60be001047008dbe0000f9ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Worm:Win32/Moarider!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Autoit.mBpQ
CynetMalicious (score: 100)
FireEyeGeneric.mg.a2c990fd8a5c0024
McAfeeGenericRXAA-AA!A2C990FD8A5C
Cylanceunsafe
ZillyaTrojan.Hesv.Win32.5585
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/Generic.04a4ae60
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZexaF.36662.rm0@ay8iSDmi
CyrenW32/S-79628cd6!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
ClamAVWin.Malware.Zusy-9956636-0
KasperskyUDS:Trojan.Win32.Hesv
BitDefenderGen:Variant.Strictor.267438
MicroWorld-eScanGen:Variant.Strictor.267438
AvastWin32:Malware-gen
TencentTrojan.Win32.Hesv.hc
EmsisoftGen:Variant.Strictor.267438 (B)
BaiduWin32.Trojan.AutoIt.a
F-SecureHeuristic.HEUR/AGEN.1363450
VIPREGen:Variant.Strictor.267438
TrendMicroTROJ_GEN.R002C0GFK23
McAfee-GW-EditionBehavesLike.Win32.RealProtect.dt
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Autoit
GDataWin32.Trojan.PSE.1K78EN9
JiangminTrojan.Hesv.dnb
AviraHEUR/AGEN.1363450
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Strictor.D414AE
ZoneAlarmUDS:Trojan.Win32.Hesv
MicrosoftWorm:Win32/Moarider!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Genome.R51444
Acronissuspicious
ALYacGen:Variant.Strictor.267438
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0GFK23
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.77674509.susgen
FortinetW32/ULPM.16C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.85ed8d
DeepInstinctMALICIOUS

How to remove Worm:Win32/Moarider!pz?

Worm:Win32/Moarider!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment