Malware

Rogue:Win32/Multiverze removal guide

Malware Removal

The Rogue:Win32/Multiverze is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue:Win32/Multiverze virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine Rogue:Win32/Multiverze?


File Info:

name: 90272ADB9C99FC75DD92.mlw
path: /opt/CAPEv2/storage/binaries/d4e83ebe8db06205f4c9d6e27a35f94ee09f1d9c387d69679b89a73e3bb4d012
crc32: C4724572
md5: 90272adb9c99fc75dd927dcdbaf5cc9b
sha1: 2cfdf94edf07dae7f6911a97c76101ef55d628a0
sha256: d4e83ebe8db06205f4c9d6e27a35f94ee09f1d9c387d69679b89a73e3bb4d012
sha512: 4830185857ca9a9282dc446389954cc4df795c0663e6200d0d6ba08d51b7a50a229fabaf13f8df3b2d0d07225a9d2513bcc6cc3f37d0bbb881b2a0f06a978014
ssdeep: 1536:/yRe+h6UR6WaeHLXTNgf5AYmxW7OINelyh9HxmEXBaY:/yPR6yJEqAcE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8830257E6550FBBD6E946309E49C97BD627E26C1271810E6B80FC902D0FF0355BC25A
sha3_384: db69737f36e64c647d4a20dc1382edeaf9be209396d5f9ce2d6f933fc1c64dc6e3520b193f525b675589f6d89bdb51db
ep_bytes: 53575655e8000000005d81ed4c130010
timestamp: 2011-07-18 07:40:49

Version Info:

0: [No Data]

Rogue:Win32/Multiverze also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.109756
FireEyeGeneric.mg.90272adb9c99fc75
CAT-QuickHealTrojan.Fosniw.B
SkyhighBehavesLike.Win32.Generic.lc
McAfeeArtemis!90272ADB9C99
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005953471 )
AlibabaTrojanDownloader:Win32/Fosniw.d75e3efe
K7GWTrojan ( 005953471 )
BitDefenderThetaGen:NN.ZexaF.36804.emW@a8ceLcg
SymantecDownloader
ESET-NOD32Win32/RiskWare.PEMalform.B
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT_017860.TOMB
AvastWin32:Evo-gen [Trj]
ClamAVWin.Trojan.Barys-9754805-0
KasperskyTrojan-Downloader.Win32.Fosniw.hoj
BitDefenderGen:Variant.Jaik.109756
NANO-AntivirusTrojan.Win32.FSPM.dfshdq
RisingPacker.Win32.Crypt.eg (CLASSIC)
EmsisoftGen:Variant.Jaik.109756 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Fosniw.2
ZillyaDownloader.Fosniw.Win32.74511
TrendMicroTROJ_AGENT_017860.TOMB
Trapminemalicious.moderate.ml.score
SophosTroj/Fosniw-F
MAXmalware (ai score=100)
JiangminTrojan/PSW.Lmir.dah
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/A-95a1fed6!Eldorado
KingsoftWin32.HeurC.KVMH008.a
MicrosoftRogue:Win32/Multiverze
XcitiumTrojWare.Win32.Kryptik.~NT@1r0f0f
ArcabitTrojan.Jaik.D1ACBC
ViRobotTrojan.Win32.A.Downloader.70656.QV
ZoneAlarmTrojan-Downloader.Win32.Fosniw.hoj
GDataWin32.Trojan.PSE.N540AG
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Fosniw.C138873
ALYacGen:Variant.Jaik.109756
VBA32Trojan.Phires
MalwarebytesMalware.AI.766667865
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderL
TencentWin32.Trojan-Downloader.Fosniw.Uimw
YandexTrojan.DL.Fosniw!OIKNJtTTvF8
IkarusTrojan-Downloader.Win32.Fosniw
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Fosniw.HOJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudRiskWare:Win/PEMalform.B

How to remove Rogue:Win32/Multiverze?

Rogue:Win32/Multiverze removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment