Trojan

Trojan.AntavmuMF.S26669779 removal

Malware Removal

The Trojan.AntavmuMF.S26669779 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AntavmuMF.S26669779 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.AntavmuMF.S26669779?


File Info:

name: 0609C16ECB02C338501C.mlw
path: /opt/CAPEv2/storage/binaries/6a1ff8f8b6a45bbb0e90ee99ab2aec0d215490e6bf2b415f98cbe9480f193866
crc32: E4C750B5
md5: 0609c16ecb02c338501c9a9ad551312b
sha1: fed59b1b717f3e78fa18c12f68c898a8f85ad281
sha256: 6a1ff8f8b6a45bbb0e90ee99ab2aec0d215490e6bf2b415f98cbe9480f193866
sha512: 0358b466ef830a1b067ceb2241af7ef3a434ac68c08bb30cc0bbf3f3d9dbfab57fcb31cf8e438d60eeb922b429488a08b11cd8ae9bc48e8ff71871032280cf8e
ssdeep: 196608:cItmhiYdvr6OlKNi6qe24ikaguWKpzBP2PHltq3wwr66pIKfLxK3L:qwy6OlKNiNvFWM+PHltqgw233L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147F6330F04295EE6F0BBD331AF2A6FCB9BB444FF02202543AB5293817994659127F677
sha3_384: 9b20938cbd1fa15879361f7b22a8bbd67791cdaa3b95c943e762a68956b90470ed18e07519dcfc31944c60a7088747c0
ep_bytes: e8e3feffff33c050505050e8542b0000
timestamp: 2009-08-16 11:05:35

Version Info:

0: [No Data]

Trojan.AntavmuMF.S26669779 also known as:

MicroWorld-eScanTrojan.GenericKD.43813914
FireEyeTrojan.GenericKD.43813914
CAT-QuickHealTrojan.AntavmuMF.S26669779
ALYacTrojan.GenericKD.43813914
VIPRETrojan.GenericKD.43813914
BitDefenderTrojan.GenericKD.43813914
K7GWNetWorm ( 700000151 )
K7AntiVirusNetWorm ( 700000151 )
ArcabitTrojan.Generic.D29C8C1A
CyrenW32/VB-BotMap-based!Maximus
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ClamAVWin.Packer.VbPack-0-6334882-0
KasperskyTrojan.Win32.Antavmu.ahnp
NANO-AntivirusTrojan.Win32.Antavmu.hvoner
SophosMal/Generic-S
ComodoBackdoor.Win32.Refpron.~AW@tosg0
DrWebTrojan.PWS.Stealer.1932
ZillyaTrojan.Antavmu.Win32.6497
McAfee-GW-EditionBehavesLike.Win32.VBObfus.vc
EmsisoftTrojan.GenericKD.43813914 (B)
APEXMalicious
JiangminWorm.WBNA.bguj
AviraTR/Antavmu.gfqyr
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.330C
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Antavmu.ahnp
GDataTrojan.GenericKD.43813914
SentinelOneStatic AI – Malicious SFX
AhnLab-V3Trojan/Win.Antavmu.C5228510
McAfeeArtemis!0609C16ECB02
VBA32Trojan.Antavmu
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Ymacco!8.11BE1 (TFE:5:pKMrvdcjj0T)
YandexTrojan.Antavmu!jOy/IypWt3w
IkarusTrojan.Antavmu
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
Cybereasonmalicious.ecb02c
AvastWin32:Malware-gen

How to remove Trojan.AntavmuMF.S26669779?

Trojan.AntavmuMF.S26669779 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment