Virus

UDS:Virus.DOS.Moctezuma.2416 malicious file

Malware Removal

The UDS:Virus.DOS.Moctezuma.2416 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Virus.DOS.Moctezuma.2416 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine UDS:Virus.DOS.Moctezuma.2416?


File Info:

name: 7B63E629C159A40AF462.mlw
path: /opt/CAPEv2/storage/binaries/17112ec307fdcced541e4909d9ad80aa274528ee7b5dcea150a0053a0a1958bb
crc32: 908B82C8
md5: 7b63e629c159a40af4628319e97a4bc9
sha1: 1838f47837977fd62ba2054f20911f8dfadbeaab
sha256: 17112ec307fdcced541e4909d9ad80aa274528ee7b5dcea150a0053a0a1958bb
sha512: 11d45fee5a86149e1f90b776d3083b6392a34c28754c1b5a33a6675ec865dbe5e4e57dd102ebaea43a6781b22c0fd987d5d05a6bdf9be3d24100e0fb21948fe1
ssdeep: 1536:HbJksB1k/ledK5QPqfhVWbdsmA+RjPFLC+e5hs0ZGUGf2g:HVksB0edNPqfcxA+HFshsOg
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T120739F62B9D0C430F45481B19D3D2E73AE7EE9540A5793F79BD4B5A4CEF0190AA0B32B
sha3_384: dc427830906d2f02b6797ac1994fa41d52b7c1a0879ff051df5ceb10053e9ba5b66fa71da31418c2dd3e6fdb6038fc0f
ep_bytes: eb1066623a432b2b484f4f4b90e928f1
timestamp: 2011-01-11 01:44:56

Version Info:

0: [No Data]

UDS:Virus.DOS.Moctezuma.2416 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.FileInfector.eGW@a0SquDf
FireEyeGeneric.mg.7b63e629c159a40a
CAT-QuickHealTrojan.Antavmu.D7
ALYacGen:Trojan.FileInfector.eGW@a0SquDf
MalwarebytesMalware.AI.1943549339
VIPREGen:Trojan.FileInfector.eGW@a0SquDf
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001f4e2b1 )
K7GWTrojan ( 001f4e2b1 )
Cybereasonmalicious.9c159a
BitDefenderThetaAI:Packer.A86A0CF01E
VirITTrojan.Win32.Generic.ABFQ
CyrenW32/Ildirim.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.OGZ
APEXMalicious
ClamAVWin.Trojan.Antavmu-523
KasperskyUDS:Virus.DOS.Moctezuma.2416
BitDefenderGen:Trojan.FileInfector.eGW@a0SquDf
NANO-AntivirusTrojan.Win32.Antavmu.dhwgp
ViRobotTrojan.Win32.A.Antavmu.74752
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Agent.mgr
EmsisoftGen:Trojan.FileInfector.eGW@a0SquDf (B)
F-SecureTrojan.TR/Antavmu.doena
DrWebTrojan.Siggen8.42052
ZillyaTrojan.KillFilesGen.Win32.1
TrendMicroTSPY_ANTAVMU_BK08301E.TOMC
McAfee-GW-EditionBehavesLike.Win32.Sality.lh
Trapminemalicious.high.ml.score
SophosMal/Antavmu-A
IkarusBackdoor.Poison
GDataGen:Trojan.FileInfector.eGW@a0SquDf
JiangminTrojan.Antavmu.chz
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Antavmu.doena
MAXmalware (ai score=81)
Antiy-AVLRiskWare[RiskTool]/Win32.Killfiles.neh
XcitiumTrojWare.Win32.KillFiles.NEH@4qfvz0
ArcabitTrojan.FileInfector.E09A77
SUPERAntiSpywareWorm.Antavmu
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Antavmu.D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Antavmu.R25058
McAfeeDropper-FAH!7B63E629C159
TACHYONWorm/W32.FileInfector.74752
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ANTAVMU_BK08301E.TOMC
RisingTrojan.Win32.Antavmu.b (CLASSIC)
YandexTrojan.GenAsa!mLg/yf6hjK0
SentinelOneStatic AI – Suspicious PE
FortinetW32/Antavmu.JWS!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove UDS:Virus.DOS.Moctezuma.2416?

UDS:Virus.DOS.Moctezuma.2416 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment