Threat Database Worms W32.Murtinda

W32.Murtinda

By ZulaZuza in Worms

W32.Murtinda is a malicious worm, which duplicates itself to spread from one computer to another. W32.Murtinda does not need a host program to proliferate itself over the Internet and computer systems. W32.Murtinda is mainly created to propagate as quickly as possible instead of changing system files and settings. W32.Murtinda can slow down your computer work and disable the network. W32.Murtinda will delete some files and change registry entries in order to avoid the detection of anti-virus software or run at Windows startup. You need to uninstall W32.Murtinda as quickly as possible once you detect it on your machine.

File System Details

W32.Murtinda may create the following file(s):
# File Name Detections
1. %ProgramFiles%\avupdate.exe
2. %DriveLetter%\Love-Story.exe
3. %SystemDrive%\av.sys
4. %ProgramFiles%\run.ini
5. %DriveLetter%\autorun.inf

Registry Details

W32.Murtinda may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\"CleanShutdown" = "0?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\"CheckedValue" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideFileExt" = "1"
HKEY_CURRENT_USER\Software\Microsoft\"C0d3R" = "MADE IN INDIA.@AzUtRuM@”"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\"Anti-Virus Update" = "%ProgramFiles%\avupdate.exe"
HKEY_CURRENT_USER\Software\Microsoft\C0d3R\"C0d3R__INFO" = "hey sniffer"

Trending

Most Viewed

Loading...