Trojan

Trojan:Win32/Multiverze (file analysis)

Malware Removal

The Trojan:Win32/Multiverze is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Multiverze virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ioxg.ix.tc

How to determine Trojan:Win32/Multiverze?


File Info:

crc32: 45DC3581
md5: ee759b97c88356e23b04afa427c6cb94
name: EE759B97C88356E23B04AFA427C6CB94.mlw
sha1: 439eba6c162e5512533ada4576de9f0e32def9d7
sha256: 5c1fec4300276bd8bd042cf24f256de87350ad32a456578da4eb364de9f3fbfc
sha512: 0447961f3ecfdfb5369cdd6f7bbc8d3455dcc8eaece606c85b9774f9c7981f26fea32133ea1c5214bbf73caea8c936257a1b349d2e7cee171f508ad1d4f050a0
ssdeep: 3072:oNWDBMze3jTiw8xIoMsivsnxnnCn0lUKraL:oIBM02wu4vsU0lUK2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: XCIX
InternalName: 2
FileVersion: 3.00.0009
CompanyName: Abronsius
LegalTrademarks: XCIX
Comments: Update
ProductName: XCIX
ProductVersion: 3.00.0009
FileDescription: Update
OriginalFilename: 2.exe

Trojan:Win32/Multiverze also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004be7cd1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader13.38206
CynetMalicious (score: 100)
CAT-QuickHealTrojan.VBCrypt.MF.50
ALYacGen:Variant.Symmi.15294
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Inject.e303ba84
K7GWTrojan ( 004be7cd1 )
Cybereasonmalicious.7c8835
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BZAS
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Generic-6760702-0
KasperskyTrojan.Win32.Inject.uyjy
BitDefenderGen:Variant.Symmi.15294
NANO-AntivirusTrojan.Win32.Inject.dwtekw
ViRobotTrojan.Win32.Inject.176128.D
MicroWorld-eScanGen:Variant.Symmi.15294
Ad-AwareGen:Variant.Symmi.15294
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34790.km0@aejG!6dO
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.ee759b97c88356e2
EmsisoftTrojan.Injector (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Inject.axkc
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.118A91C
MicrosoftTrojan:Win32/Multiverze
GDataGen:Variant.Symmi.15294
TACHYONTrojan/W32.VB-Injector.176128
AhnLab-V3Malware/Gen.RL_Generic.R355105
Acronissuspicious
McAfeeBackDoor-FDDH!EE759B97C883
MAXmalware (ai score=85)
VBA32TScope.Trojan.VB
MalwarebytesMalware.AI.221949655
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R06CC0PGA21
IkarusTrojan.Win32.Xrat
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.UYJY!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360HEUR/QVM03.0.8113.Malware.Gen

How to remove Trojan:Win32/Multiverze?

Trojan:Win32/Multiverze removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment