Worm

Should I remove “Worm:Win32/Morto.D”?

Malware Removal

The Worm:Win32/Morto.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Morto.D virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Worm:Win32/Morto.D?


File Info:

name: 1676B007C6F3892750DB.mlw
path: /opt/CAPEv2/storage/binaries/a7a28d255225a456c57c8526b84ffd8bb0304d8b7dc8d80c8d2c07f268f6b6cb
crc32: 7FA168CB
md5: 1676b007c6f3892750dbde6e68d6185f
sha1: 354ef6db9a1ab2a35696e048689a75e76d8286b4
sha256: a7a28d255225a456c57c8526b84ffd8bb0304d8b7dc8d80c8d2c07f268f6b6cb
sha512: 333904efafd0295774ac914db4400cd1c69bb0c56bd7df2c7f70d5f0d97e24b2e369ec2ad6d7c179ed2eac6f1cbacbea71a629c0b6a04d47af963a8e4e436304
ssdeep: 384:45FFSzBMDsldRB0oavALdGp9MzV0uXVs6+ax:4HgzTav4dM9MzvF5P
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1CB6228574F8A33E6F4692378265A593B65AAF430100DA02ECFB27EDF0B349C4C61752C
sha3_384: 9ffdc6440732edd8f647b328c6bd877fd9c03d622e8fff6cc8113bc8c9545ceb23d4dd8764927ce2f0af74efec2278a5
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2011-12-06 14:26:05

Version Info:

CompanyName:
FileDescription: Loader2 DLL
FileVersion: 1, 0, 0, 1
InternalName: Loader2
LegalCopyright: 版权所有 (C) 2011
LegalTrademarks:
OriginalFilename: Loader2.DLL
ProductName: Loader2 Dynamic Link Library
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Worm:Win32/Morto.D also known as:

LionicTrojan.Win32.Generic.lsE8
MicroWorld-eScanGen:Variant.Barys.451247
FireEyeGeneric.mg.1676b007c6f38927
CAT-QuickHealWorm.Morto.D
SkyhighW32/Morto.dll.b
McAfeeW32/Morto.dll.b
Cylanceunsafe
ZillyaWorm.Morto.Win32.59
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaWorm:Win32/Morto.378af3cb
K7GWTrojan ( 0033f4031 )
K7AntiVirusTrojan ( 0033f4031 )
BitDefenderThetaGen:NN.ZedlaF.36744.au8@aaugx7kb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Morto.S
APEXMalicious
ClamAVWin.Virus.Morto-2538
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.451247
NANO-AntivirusTrojan.Win32.Morto.oufxm
SUPERAntiSpywareWorm.Morto
AvastWin32:Morto-E [Wrm]
TencentWorm.Win32.Morto.h
EmsisoftGen:Variant.Barys.451247 (B)
GoogleDetected
F-SecureWorm.WORM/Morto.dlnam
VIPREGen:Variant.Barys.451247
TrendMicroWORM_MORTO.SM2
SophosMal/Generic-S
IkarusWorm.Win32.Morto
GDataGen:Variant.Barys.451247
JiangminTrojan/Generic.wduu
WebrootWorm.W32.Morto
VaristW32/FraudLoad.D.gen!Eldorado
AviraWORM/Morto.dlnam
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
XcitiumWorm.Win32.Morto.~dln@4lnkjr
ArcabitTrojan.Barys.D6E2AF
ZoneAlarmUDS:Trojan.Win32.Generic
MicrosoftWorm:Win32/Morto.D
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Morto.R17482
ALYacGen:Variant.Barys.451247
MAXmalware (ai score=100)
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_MORTO.SM2
RisingWorm.Win32.Morto.h (CLASSIC)
YandexTrojan.GenAsa!zDHpTi0QOFo
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Morto.A!tr
AVGWin32:Morto-E [Wrm]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Morto.D?

Worm:Win32/Morto.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment