Home Malware Programs Worms Worm:MSIL/Murkados.A

Worm:MSIL/Murkados.A

Posted: May 23, 2013

Threat Metric

Threat Level: 5/10
Infected PCs: 117
First Seen: May 23, 2013
Last Seen: September 12, 2019
OS(es) Affected: Windows

Worm:MSIL/Murkados.A is a worm, which circulates via removable drives. Worm:MSIL/Murkados.A downloads Chrome web browser extension files that change the way the web browser operates. Worm:MSIL/Murkados.A is distributed by affecting removable devices, such as a USB stick or flash drive. When installed on the infected computer, Worm:MSIL/Murkados.Amakes system changes by downloading the potentially malicious files and making registry modifications to assure it loads automatically every time Windows starts. Worm:MSIL/Murkados.A may also close Google Chrome Internet browser unexpectedly. Once run, Worm:MSIL/Murkados.A replicates itself to the certain location. Worm:MSIL/Murkados.A searches the infected computer to find 'chrome.exe'. This file indicates that the PC user has the Google Chrome Internet browser installed on the machine. If it finds 'chrome.exe', it renames it to new_chrome.exe. The worm then copies itself to 'chrome.exe'. Worm:MSIL/Murkados.A checks for any removable drives connected to the targeted computer. If Worm:MSIL/Murkados.A finds any removable drives with a 'security.exe' file, it replicates itself onto the drive as 'security.exe'.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\ProgramData\start.exe File name: c:\ProgramData\start.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Chrome New" = "c:\programdata\start.exe"
Loading...