Virus

Virus.DOS.Moctezuma.2416 removal

Malware Removal

The Virus.DOS.Moctezuma.2416 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.DOS.Moctezuma.2416 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a registry key
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Virus.DOS.Moctezuma.2416?


File Info:

crc32: B195BFEE
md5: 4fab3f66348b054c3eec545a76ab4604
name: 4FAB3F66348B054C3EEC545A76AB4604.mlw
sha1: 1b31a33a9eceb14934bae10e4bef3d9ec71ee0e2
sha256: 5b689da60eb0407c3e5a392b4496dfb477d17ec41444bcc0d9175e9c649a28d9
sha512: cac0c9474ca0675e61da7e7f12ba47cf57fac793cd5d54f3028d5cbe0c62e89f1eb38795df887b751154ee0830ab7654ad689c8c01d944bb32986f3fd25565b9
ssdeep: 1536:HbzOuQwhjK5QPqfhVWbdsmA+RjPFLC+e5hU0ZGUGf2g:Hf31hjNPqfcxA+HFshUOg
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Virus.DOS.Moctezuma.2416 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.FileInfector.eGW@a0SquDf
FireEyeGeneric.mg.4fab3f66348b054c
CAT-QuickHealTrojan.Antavmu.D7
McAfeeDropper-FAH!4FAB3F66348B
CylanceUnsafe
VIPRETrojan.Win32.Antavmu.d (v)
SangforMalware
K7AntiVirusTrojan ( 001f4e2b1 )
BitDefenderGen:Trojan.FileInfector.eGW@a0SquDf
K7GWTrojan ( 001f4e2b1 )
Cybereasonmalicious.6348b0
CyrenW32/Ildirim.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Antavmu.HM
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Antavmu-523
KasperskyVirus.DOS.Moctezuma.2416
NANO-AntivirusTrojan.Win32.Antavmu.dhwgp
ViRobotTrojan.Win32.A.Antavmu.74752
RisingTrojan.Win32.Antavmu.b (RDMK:cmRtazpWw5ADnFGPCqRZgyE/i9y/)
Ad-AwareGen:Trojan.FileInfector.eGW@a0SquDf
EmsisoftGen:Trojan.FileInfector.eGW@a0SquDf (B)
ComodoTrojWare.Win32.KillFiles.NEH@4qfvz0
F-SecureTrojan.TR/Antavmu.doena
DrWebTrojan.Siggen8.42052
ZillyaTrojan.KillFilesGen.Win32.1
TrendMicroTSPY_ANTAVMU_BK08301E.TOMC
McAfee-GW-EditionDropper-FAH!4FAB3F66348B
SophosML/PE-A + Mal/Antavmu-A
IkarusBackdoor.Poison
JiangminTrojan.Antavmu.chz
AviraTR/Antavmu.doena
MAXmalware (ai score=85)
Antiy-AVLRiskWare[RiskTool]/Win32.Killfiles.neh
MicrosoftTrojan:Win32/Antavmu.D
ArcabitTrojan.FileInfector.E09A77
SUPERAntiSpywareWorm.Antavmu
ZoneAlarmVirus.DOS.Moctezuma.2416
GDataGen:Trojan.FileInfector.eGW@a0SquDf
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Antavmu.R25058
Acronissuspicious
BitDefenderThetaAI:Packer.A86A0CF01E
ALYacGen:Trojan.FileInfector.eGW@a0SquDf
TACHYONWorm/W32.FileInfector.74752
VBA32BScope.Trojan.Downloader
MalwarebytesVirus.Injector
PandaTrj/Genetic.gen
ESET-NOD32Win32/Agent.OGZ
TrendMicro-HouseCallTSPY_ANTAVMU_BK08301E.TOMC
TencentTrojan.Win32.Agent.mgr
YandexTrojan.GenAsa!mLg/yf6hjK0
SentinelOneStatic AI – Malicious PE – Downloader
FortinetW32/Antavmu.JWS!tr
WebrootW32.Trojan.Gen
AVGFileRepMalware
Qihoo-360Generic/Virus.DoS.e7e

How to remove Virus.DOS.Moctezuma.2416?

Virus.DOS.Moctezuma.2416 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment