Worm

What is “Worm:Win32/Morto!A”?

Malware Removal

The Worm:Win32/Morto!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Morto!A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify desktop wallpaper
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics

How to determine Worm:Win32/Morto!A?


File Info:

crc32: 17A5582A
md5: bafc01d36fdf6f5540baf1bc53bbbf39
name: BAFC01D36FDF6F5540BAF1BC53BBBF39.mlw
sha1: 194cfb028b9d293e05cee39d0343ec21bf056d02
sha256: d5f45b360aa5c33d32c9cd90662b14ca62ea53bea507305139d584447d0f1d01
sha512: dd50884c8601c5550ae5dc7de061da58de9c38624c91713a9a47c441202a2175471e08ef85240f7d431ba22a1d734f96bd22a2cedc6e23292704109cc8c074a2
ssdeep: 1536:q4cQylcAbqJAyx0rrPsHPbk49aB0lG3k68Ftu3mDuKIZHwsAZZfLFrwh:Ny2RJAXfPsv6UtlqYjDF8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Morto!A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 002b0fe41 )
Elasticmalicious (high confidence)
DrWebBackDoor.Tsclient.1
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.emGfXDuej1b
CylanceUnsafe
ZillyaWorm.Morto.Win32.63
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Morto.eb2f8989
K7GWTrojan ( 002b0fe41 )
Cybereasonmalicious.36fdf6
BaiduWin32.Worm.Morto.f
SymantecTrojan.Dropper
ESET-NOD32Win32/Patched.NCE
APEXMalicious
TotalDefenseWin32/Inpect.10
AvastWin32:Malware-gen
ClamAVWin.Worm.Morto-520
KasperskyTrojan-Ransom.Win32.Gpcode.ce
BitDefenderGen:Trojan.Heur.emGfXDuej1b
NANO-AntivirusTrojan.Win32.Gpcode.tmtkd
ViRobotWorm.Win32.A.Net-Morto.68096
MicroWorld-eScanGen:Trojan.Heur.emGfXDuej1b
TencentWin32.Trojan.Gpcode.Pjxk
Ad-AwareGen:Trojan.Heur.emGfXDuej1b
SophosMal/Generic-S
ComodoTrojWare.Win32.Spy.SCKeyLog.x1@1cd3uo
BitDefenderThetaAI:Packer.37587F991B
VIPRETrojan.Win32.Morto.c (v)
TrendMicroCryp_Xed-16
McAfee-GW-EditionBehavesLike.Win32.Generic.kc
FireEyeGeneric.mg.bafc01d36fdf6f55
EmsisoftGen:Trojan.Heur.emGfXDuej1b (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Morto.fex
WebrootW32.Trojan.Gen
AviraWORM/Morto.A
eGambitUnsafe.AI_Score_99%
MicrosoftWorm:Win32/Morto.gen!A
ZoneAlarmTrojan-Ransom.Win32.Gpcode.ce
GDataGen:Trojan.Heur.emGfXDuej1b
TACHYONWorm/W32.Morto.68096
Acronissuspicious
McAfeeMultiDropper-BU
MAXmalware (ai score=100)
VBA32OScope.Worm.Morto.3821
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallCryp_Xed-16
RisingDropper.Win32.Mnless.emv (CLOUD)
YandexTrojan.GenAsa!4WESCi+5MMI
IkarusWorm.Win32.Morto
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Morto.B!worm.im
AVGWin32:Malware-gen
Qihoo-360Worm.Win32.Morto.A

How to remove Worm:Win32/Morto!A?

Worm:Win32/Morto!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment