Malware

About “Downloader.Morstar” infection

Malware Removal

The Downloader.Morstar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Morstar virus can do?

  • Executable code extraction
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Downloader.Morstar?


File Info:

crc32: C3CFFAF8
md5: 0c2fb31d478ad0d442b4c41879211fee
name: 0C2FB31D478AD0D442B4C41879211FEE.mlw
sha1: 7f7f4fb760c80ad44e31b3f2462a5f57e3c4cfb8
sha256: 906b35eae8d328f1a8fc0bbf14d07b50167a34acaad5bb8dcfc7517d13cc2d8e
sha512: 1787eacc05bbf894e7324fce2f3596add594107e6893c3c98809816877195537d37726b5dd1b8507f606c99a699beaf4ef328e6312d0cf238cc7f8b8b36fd301
ssdeep: 24576:aMI2+tkzV/78cxXtXOTo4Nq9Hr5qrKWx4R8ZhnVl4PTwGWPN5:1IXSgMtmo4M9L5cjSanVl4PG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2003-2014 Fco Orlando Magalhaes Filho. All rights reserved.
InternalName: XLtoEXE
FileVersion: 2.00.0005
CompanyName: Orlando's VBA and Excel Site
LegalTrademarks: Microsoftxae Excelxae is a registered trademark of Microsoft Corporation.
ProductName: XLtoEXE
ProductVersion: 2.00.0005
FileDescription: Excel application converted by XLtoEXE utility.
OriginalFilename: XLtoEXE.exe
Translation: 0x0409 0x04b0

Downloader.Morstar also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.MulDrop6.18954
ClamAVWin.Malware.Unsafe-6821429-0
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Bcex.Win32.68
SangforTrojan.Win32.Save.a
Cybereasonmalicious.760c80
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cc
FireEyeGeneric.mg.0c2fb31d478ad0d4
EmsisoftApplication.Generic (A)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Heur.KVM007.a.(kcloud)
McAfeeArtemis!0C2FB31D478A
VBA32Downloader.Morstar
RisingMalware.FakeXLS/ICON!1.6AC3 (CLASSIC)
YandexTrojan.Agent!OKJbX+rEa2k
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/VbCrypt.1600!tr
AVGWin32:Malware-gen

How to remove Downloader.Morstar?

Downloader.Morstar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment