Trojan

What is “Trojan.Win32.Antavmu.aste”?

Malware Removal

The Trojan.Win32.Antavmu.aste is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Antavmu.aste virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Win32.Antavmu.aste?


File Info:

crc32: 4E4D883C
md5: 981835ea9f0a719458d150065b3b14b4
name: 981835EA9F0A719458D150065B3B14B4.mlw
sha1: 2d4aebc78d567bb55e20872641df9e758684393d
sha256: 34f37327a0154d644854a723e0557c733931e2366a19bdb4cfe6f6ae6770c50f
sha512: d4bd7c200992c8ec84726bf6277a3f5ee9684d3e7824a8c4a280d64ae25a5592c74d073ba01002f13be98d80e47bab87f5a044959f648fe7cf6d4debcb4174aa
ssdeep: 6144:BuVCwpxoVgRQBaj3x3fQ/3Xw3ah3x+zu8hWUp/RLG/oPRYYayHiS:BuVAQjh3fQ/nw0x+zu8tg0RO2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TODO: (C) x3002x4fddx7559x6240x6709x6743x5229x3002
InternalName: KugouUI.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: KugouUI.exe
Translation: 0x0804 0x03a8

Trojan.Win32.Antavmu.aste also known as:

K7AntiVirusTrojan ( 0057b7931 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Antavmu
ALYacTrojan.Agent.Antavmu
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3224417
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Antavmu.1d975a50
K7GWTrojan ( 0057b7931 )
CyrenW32/Trojan.VARP-4920
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKOG
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Antavmu.aste
BitDefenderTrojan.GenericKD.46343208
MicroWorld-eScanTrojan.GenericKD.46343208
Ad-AwareTrojan.GenericKD.46343208
ComodoMalware@#10elwgtwynkgn
BitDefenderThetaGen:NN.ZexaF.34722.Bq3@aKGa8gej
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03FC0PEP21
McAfee-GW-EditionRDN/Generic.rp
FireEyeGeneric.mg.981835ea9f0a7194
EmsisoftTrojan.GenericKD.46343208 (B)
JiangminBackdoor.Generic.bstv
AviraTR/AD.Farfli.zieel
eGambitUnsafe.AI_Score_75%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Emotet!ml
GDataWin32.Trojan.PSE.1SYPIY7
AhnLab-V3Trojan/Win.Agent.R417294
McAfeeRDN/Generic.rp
MAXmalware (ai score=100)
VBA32BScope.Trojan.Tnega
MalwarebytesMalware.AI.2245317090
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03FC0PEP21
RisingTrojan.Kryptik!1.D571 (CLASSIC)
YandexTrojan.Antavmu!rEBgu652Xi8
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HKOG!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Antavmu.aste?

Trojan.Win32.Antavmu.aste removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment