Solved! Use MIRAA .EXE (Trojan Agent) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

MIRAA .EXE – Trojan Agent removal

File MD5 Virus Alias
MIRAA .EXE ed03b1b4384f5a74fc2a14624f0653de Trojan Agent
MIRAA .EXE ed03b1b4384f5a74fc2a14624f0653de Trojan ZBot

MIRAA .EXE size: 512382 bytes
MIRAA .EXE hash: ED03B1B4384F5A74FC2A14624F0653DE

Created files:

C:\. .exe
C:\.. .exe
C:\AUTOEXEC.BAT .exe
C:\boot.ini .exe
C:\CONFIG.SYS
C:\CONFIG.SYS .exe
C:\Documents and Settings .exe
C:\IO.SYS
C:\IO.SYS .exe
C:\killok .exe
C:\Mirat
C:\Mirat .exe
C:\MSDOS.SYS
C:\MSDOS.SYS .exe
C:\NTDETECT.COM
C:\NTDETECT.COM .exe
C:\ntldr
C:\ntldr .exe
C:\pagefile.sys .exe
%Program Files% .exe
C:\Sandbox .exe
C:\Sandboxie .exe
C:\scan.cmd .exe
C:\System Volume Information .exe
%WinDir% .exe
D:\. .exe
D:\.. .exe
D:\32Bit .exe
D:\64Bit .exe
D:\AUTORUN.INF .exe
D:\autorun.sh
D:\autorun.sh .exe
D:\cert .exe
D:\Miraa
D:\Miraa .exe
D:\OS2 .exe
D:\runasroot.sh
D:\runasroot.sh .exe
D:\VBoxLinuxAdditions.run
D:\VBoxLinuxAdditions.run .exe
D:\VBoxSolarisAdditions.pkg
D:\VBoxSolarisAdditions.pkg .exe
D:\VBoxWindowsAdditions-amd64.exe
D:\VBoxWindowsAdditions-amd64.exe .exe
D:\VBoxWindowsAdditions-x86.exe
D:\VBoxWindowsAdditions-x86.exe .exe
D:\VBoxWindowsAdditions.exe
D:\VBoxWindowsAdditions.exe .exe
%Common AppData%\fxoyo.exe

Autostart registry keys:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft? Windows? Operating System: %Common AppData%\fxoyo.exe

Detected by UnHackMe:

MIRAA .EXE
Default location: D:\MIRAA .EXE

Dropper information:
MD5: d7372d32bb61c673c2614a846c831bc0
File size: 741819 bytes

Leave a Reply