Home Malware Programs Worms Worm.Morto.D

Worm.Morto.D

Posted: January 19, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 5
First Seen: January 19, 2012
OS(es) Affected: Windows

Worm.Morto.D is a worm that invades the affected Windows computers for spreading its main payload that it gains from a remote server. Worm.Morto.D can easily connect to the Internet without the PC user's awareness and execute a variety of malicious actions that can harm the targeted PC. Worm.Morto.D replicates itself in order to proliferate to other computers. Worm.Morto.D checks the network and looks for PCs that are connected through RDP sessions (Remote Desktop service) and notes down all the IP addresses that can be found in the affected computer's subnet, so that Worm.Morto.D could connect to those computers using particular user names and passwords. Worm.Morto.D downloads and installs other malware threats on the corrupted PC. Worm.Morto.D also gains commands from a remote server to launch a Denial of Service (DoS) attacks against certain servers and websites.

Aliases

Generic Worm [Panda]Worm/Generic2.BCRW [AVG]W32/Morto.ECA!worm [Fortinet]Worm.Win32.Morto [Ikarus]Worm/Win32.Morto [AhnLab-V3]Worm:Win32/Morto.D [Microsoft]Worm/Win32.Morto.gen [Antiy-AVL]Win32/Morto.F [eTrust-Vet]Worm/Morto.dllpn [AntiVir]Worm.Win32.Morto.~J [Comodo]Mal/Morto-A [Sophos]Net-Worm.Win32.Morto.eca [Kaspersky]Worm.Morto-4 [ClamAV]Win32:Morto-D [Wrm] [Avast]W32/Morto.D.gen!Eldorado [F-Prot]
More aliases (29)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\offline web pages\cache.txt File name: cache.txt
Size: 46.08 KB (46080 bytes)
MD5: dfff75cef0f15f1d25e43a0657f0b233
Detection count: 5
Mime Type: unknown/txt
Path: %WINDIR%\offline web pages
Group: Malware file
Last Updated: January 19, 2012
Loading...