Malware

Flooder:Win32/Multiverze removal instruction

Malware Removal

The Flooder:Win32/Multiverze is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Flooder:Win32/Multiverze virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Flooder:Win32/Multiverze?


File Info:

name: 89A9A27FA90571777763.mlw
path: /opt/CAPEv2/storage/binaries/980f92e519ac6bfe20320bce7ee4e1a6d37127f9e8dfd8f051e1fcf4af39194c
crc32: E710713C
md5: 89a9a27fa90571777763fb7f3edcd632
sha1: b25575fa3ec067b31b2fa845872451cd80ccea39
sha256: 980f92e519ac6bfe20320bce7ee4e1a6d37127f9e8dfd8f051e1fcf4af39194c
sha512: 266b7c6c3d0baf133f5c8cff8cfa10b6957f25ba18dec289d1959618c661300c58a632f0df881185081e57872f274856d920a8676846438a62e74020e756c5bb
ssdeep: 1536:LJaPJpAz869DUxWB+i4OQ4NR2Kk+aSnfZaG8fcaOCzGquSE0cF+vK:LJ0TAz6Mte4A+aaZx8EnCGVuv
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10883021646DF58F7E49B027D469D9063B1FBA06F4BCE3EDBE1FC124DC6162B01580248
sha3_384: 9dcdfc4dbcf8660b20a4d29cc8d32e035bb7cb07f3c0fe922452d543ac4d66ff8dc1790986130e0ecdc0f2b8887976ab
ep_bytes: 60be154041008dbeebcffeff5783cdff
timestamp: 2014-07-01 18:02:13

Version Info:

0: [No Data]

Flooder:Win32/Multiverze also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
ClamAVWin.Malware.Cymt-10023133-0
SkyhighBehavesLike.Win32.BadFile.mc
ALYacApplication.Agent.BPO
Cylanceunsafe
SangforTrojan.Win32.Agent.Vggx
K7AntiVirusTrojan ( 00575d031 )
BitDefenderApplication.Agent.BPO
K7GWTrojan ( 00575d031 )
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitApplication.Agent.BPO
VirITTrojan.Win32.AgentT.DYK
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Agent.AAEF
CynetMalicious (score: 100)
KasperskyHEUR:Flooder.Win32.CoreWarrior.gen
AlibabaTrojanDownloader:Win32/CoreWarrior.49a4c46c
NANO-AntivirusTrojan.Win32.Snojan.jqzopm
MicroWorld-eScanApplication.Agent.BPO
AvastWin32:Banker-LAA [Trj]
RisingDownloader.Snojan!8.ECDD (TFE:5:V47YrAkOYKG)
EmsisoftApplication.Agent.BPO (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen2
DrWebTool.Snojan.1
ZillyaTrojan.Agent.Win32.3906285
TrendMicroTROJ_GEN.R03BC0DDB24
Trapminesuspicious.low.ml.score
FireEyeApplication.Agent.BPO
SophosTroj/Bdoor-BHD
SentinelOneStatic AI – Suspicious PE
JiangminDownloader.Snojan.adp
GoogleDetected
AviraTR/Crypt.ULPM.Gen2
MAXmalware (ai score=76)
Antiy-AVLTrojan/Win32.Phonzy
XcitiumTrojWare.Win32.Snojan.B@7h1cjp
MicrosoftFlooder:Win32/Multiverze
ZoneAlarmHEUR:Flooder.Win32.CoreWarrior.gen
GDataWin32.Application.Snojan.A
VaristW32/Agent.FBOO-5422
Acronissuspicious
McAfeeArtemis!89A9A27FA905
VBA32Flooder.CoreWarrior
MalwarebytesMalware.AI.1754406724
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DDB24
TencentTrojan.Win32.GenKryptik.kac
YandexTrojan.GenAsa!+IN19GpQULE
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.159307391.susgen
FortinetRiskware/Snojan
BitDefenderThetaGen:NN.ZexaF.36802.fmGfaC@Dadi
AVGWin32:Banker-LAA [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Nemucod

How to remove Flooder:Win32/Multiverze?

Flooder:Win32/Multiverze removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment