Adware

Adware:Win32/Multiverze removal tips

Malware Removal

The Adware:Win32/Multiverze is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Multiverze virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware:Win32/Multiverze?


File Info:

name: A2704053448CE9D7351E.mlw
path: /opt/CAPEv2/storage/binaries/5e00c5625ff7bbd39b500a8b6eba2506d5ce1c96953fa6c9016b8aa056f66d78
crc32: FAA8CF56
md5: a2704053448ce9d7351e46b01998400c
sha1: 34039635dee93e9b3c29d66896a12f0da968015b
sha256: 5e00c5625ff7bbd39b500a8b6eba2506d5ce1c96953fa6c9016b8aa056f66d78
sha512: 166235d8bc067aba29ba23c26b77a89407646d4c6987b9c11f4a24b103f87dc9173aa4293b94c3e41a65b351bbe0b6f88613940793876d8451ac1360adac9c4f
ssdeep: 196608:fbRbw8/NdMqb/BZJC/szJP7+4VUMXdEUKYTp0kEkjSYca6:fBnPJZJC4J64xNEUdSyjVca6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15986038CDC37EF20F9E4307C19592F883A58CBE8548D271AF45ABE20A64E95D127E7D4
sha3_384: 04df09a784fddc658ba2a7655112e8d3498e9a77d5287640d019e9ddca0abf89a9ef2db1e0f4bca573270c5167f79ea0
ep_bytes: 558bec6aff6820514000680430400064
timestamp: 2013-08-31 09:33:24

Version Info:

0: [No Data]

Adware:Win32/Multiverze also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.ArchSMS.4!c
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.4371
MicroWorld-eScanGen:Adware.SMSHoax.3
FireEyeGeneric.mg.a2704053448ce9d7
CAT-QuickHealHoax.ArchSMS.14383
SkyhighBehavesLike.Win32.Downloader.rc
McAfeeTrojan-FDGD!A2704053448C
Cylanceunsafe
ZillyaTrojan.ArchSMS.Win32.19155
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.23734804
K7GWTrojan ( 004e360d1 )
K7AntiVirusTrojan ( 004e360d1 )
BitDefenderThetaGen:NN.ZexaF.36802.@@Z@aWE9nZjI
VirITTrojan.Win32.FakeAV.AQOA
SymantecPUA.Gen.2
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BJIC
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R014C0PCA24
AvastWin32:SMSSend-BUC [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Adware.SMSHoax.3
NANO-AntivirusTrojan.Win32.Webalta.djhsor
EmsisoftGen:Adware.SMSHoax.3 (B)
F-SecureTrojan.TR/Fraud.Gen7
VIPREGen:Adware.SMSHoax.3
TrendMicroTROJ_GEN.R014C0PCA24
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusAdWare.Smshoax
GDataGen:Adware.SMSHoax.3
AviraTR/Fraud.Gen7
VaristW32/SMShoax.P.gen!Eldorado
Antiy-AVLHackTool[Hoax]/Win32.ArchSMS
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Injector.AKHI@51h0n1
ArcabitAdware.SMSHoax.3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftAdware:Win32/Multiverze
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.ArchSMS.R79113
Acronissuspicious
VBA32Trojan.SMSSend
ALYacGen:Adware.SMSHoax.3
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TencentWin32.Trojan.Generic.Jajl
YandexTrojan.GenAsa!TMgPrNJPZc0
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Injector.ALEK!tr
AVGWin32:SMSSend-BUC [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/SMSHoax

How to remove Adware:Win32/Multiverze?

Adware:Win32/Multiverze removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment