Trojan

How to remove “Trojan:Win32/Multsarch.Q”?

Malware Removal

The Trojan:Win32/Multsarch.Q is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Multsarch.Q virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Multsarch.Q?


File Info:

name: 2969DE05C1FAE8BCB79E.mlw
path: /opt/CAPEv2/storage/binaries/de7f6812b0fde739c0119fdcd938a35d22021c669cb09de85ceb4297cbee6ef8
crc32: 49BB7CB4
md5: 2969de05c1fae8bcb79ed830b40939b4
sha1: c61fa2d0fc733936138b925352db23a8a48e3470
sha256: de7f6812b0fde739c0119fdcd938a35d22021c669cb09de85ceb4297cbee6ef8
sha512: a7c3e68965a7226489917d282ecdc9ba16069ada176ea06e6be191737b41c07638beeebbe1a2c8a8f4579b2b40688a62130abae89fe91c2d5d0d4394e413bb6a
ssdeep: 393216:m+h/RETPH3oZ37qj5K8cuWcbJa96UE6jNDP:tcSWKbuba861
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133E633B963CA7ED2C64C9E7809997665D8F309F45C382FC16C37C2E948FC0A9C2AB155
sha3_384: 31921495948d60907ebd93b4b0b7a863293af3f53e01166a732867dc1fd25fc7d38faf5f2b8bbd7cdd02a1687f03e122
ep_bytes: 60be00b0d1008dbe00606effc787ec90
timestamp: 2008-09-26 22:50:52

Version Info:

0: [No Data]

Trojan:Win32/Multsarch.Q also known as:

LionicHacktool.Win32.ArchSMS.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.8526387
FireEyeGeneric.mg.2969de05c1fae8bc
ALYacTrojan.Generic.8526387
CylanceUnsafe
ZillyaTrojan.Diple.Win32.651
SangforSuspicious.Win32.Evo.gen
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojan:Win32/ArchSMS.509dffa8
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.5c1fae
VirITTrojan.Win32.ArchSMS.ICSH
CyrenW32/Kryptik.DKT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LZM
APEXMalicious
ClamAVWin.Trojan.Archsms-145
KasperskyHoax.Win32.ArchSMS.icsh
BitDefenderTrojan.Generic.8526387
NANO-AntivirusTrojan.Win32.SMSSend.cjlvu
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b6ac60
Ad-AwareTrojan.Generic.8526387
SophosMal/Generic-S
ComodoApplicUnwnt.Win32.Hoax.ArchSMS.ICSH@440zh9
DrWebTrojan.SMSSend.438
VIPREPacked.Win32.PWSZbot.gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.Generic.8526387 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.8526387
JiangminHoax.ArchSMS.wd
WebrootW32.Archsms
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Generic.D821A33
ZoneAlarmHoax.Win32.ArchSMS.icsh
MicrosoftTrojan:Win32/Multsarch.Q
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Diple.R9722
McAfeeGenericRXAA-AA!2969DE05C1FA
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_ARCHSMS_0000018.TOMA
RisingTrojan.Win32.Obfuscator.fuq (CLOUD)
IkarusHoax.Win32.ArchSMS
MaxSecureTrojan.Malware.2247571.susgen
FortinetRiskware/HoaxArchSMS
BitDefenderThetaGen:NN.ZexaF.34212.@pJfa0CC7doc
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan:Win32/Multsarch.Q?

Trojan:Win32/Multsarch.Q removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment