Trojan

Trojan.Win32.Antavmu removal guide

Malware Removal

The Trojan.Win32.Antavmu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Antavmu virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Singapore)
  • Authenticode signature is invalid
  • CAPE detected the Nitol malware family

How to determine Trojan.Win32.Antavmu?


File Info:

name: 88D180D88514A962C522.mlw
path: /opt/CAPEv2/storage/binaries/cb613f0cbb81b11d527d2148d0e1a5b4b89a0c7ae64b8abf0220880e9925e12a
crc32: FECAB01E
md5: 88d180d88514a962c522f82064b79b58
sha1: 26bc8bc956344e842e920ebaf4a6db6896c21064
sha256: cb613f0cbb81b11d527d2148d0e1a5b4b89a0c7ae64b8abf0220880e9925e12a
sha512: ee3dd8d0326918eb3acfd989351dbc323afa2c9204b6f1f3752ac6a239fff65d6524ae773b143387eb97a0491d3dc0e11bc8d67192406a26863389bd89985e39
ssdeep: 98304:P1hQ/zskb2qhhjqL/8JxpagB22mr/bXr+MlT+6:Xszs8zi/d2mr/X+MlT+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8066A59BB404CB7C12302315E38F239A5EDE570097E4E87EADFB62C3F65192462A17B
sha3_384: fcf11ae4f3a3b7fe220fd46c3736b450abca11ad15acb0cf235adc6eb8c6c107ced7bcec776a8a128fe06805416b823d
ep_bytes: e89f0c0000e937feffffc3558bec8b45
timestamp: 2021-12-09 22:57:53

Version Info:

FileDescription: MediaPlay2 Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: MediaPlay2
LegalCopyright: 版权所有 (C) 2013
OriginalFilename: MediaPlay2.EXE
ProductName: MediaPlay2 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Trojan.Win32.Antavmu also known as:

MicroWorld-eScanTrojan.GenericKD.38241618
FireEyeGeneric.mg.88d180d88514a962
McAfeeArtemis!88D180D88514
CylanceUnsafe
K7AntiVirusTrojan ( 005605201 )
AlibabaBackdoor:Win32/Injector.08cd0c8f
K7GWTrojan ( 005605201 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EHWE
KasperskyHEUR:Trojan.Win32.Antavmu.gen
BitDefenderTrojan.GenericKD.38241618
AvastWin32:Trojan-gen
TencentWin32.Trojan.Injector.Ednt
Ad-AwareTrojan.GenericKD.38241618
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
EmsisoftTrojan.GenericKD.38241618 (B)
GDataTrojan.GenericKD.38241618
AviraTR/Injector.nfbmn
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.38241618
MAXmalware (ai score=82)
MalwarebytesBackdoor.Farfli
TrendMicro-HouseCallTROJ_GEN.R002H0DLA21
FortinetW32/EHWE!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Trojan.Win32.Antavmu?

Trojan.Win32.Antavmu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment