Trojan

How to remove “Trojan.Win32.AntiAV.cwau”?

Malware Removal

The Trojan.Win32.AntiAV.cwau is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.AntiAV.cwau virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
robotatten.com

How to determine Trojan.Win32.AntiAV.cwau?


File Info:

crc32: 8FD341FC
md5: f4e7f2f72c43fd2ec530ac5b6d81c88f
name: dvd-cloner201815-rtmd-agxfnf6tvaaatbecaerffwamafyizlka.exe
sha1: e8787244f6a5bbe1dcc9692f82dfb99f7de61207
sha256: 97a6ed200c0e598bdde4dbdd15ae3239d2617e99e644518bfc3d612005d2ee81
sha512: 3cc0f528bb45ad481f43903b99dd649c1f26bcbbac130f4bfd7965d7d1e42a33ab78aa091c1b2611eba2b6fe4ced2d739613d66855be48a3aaa9e75bcdd4c78c
ssdeep: 98304:Becbmo4SqXUhXrvMtAH0HC4Eo4cTTKJP:M2mo4nXUhXrvMQ4OcyP
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.AntiAV.cwau also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.42837438
ALYacTrojan.GenericKD.42837438
SangforMalware
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4f6a5b
CyrenW32/Trojan.PHCM-8173
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
KasperskyTrojan.Win32.AntiAV.cwau
BitDefenderTrojan.GenericKD.42837438
AegisLabRiskware.Win32.Malicious.1!c
RisingTrojan.AntiAV!8.9C4 (CLOUD)
Endgamemalicious (high confidence)
F-SecureTrojan.TR/AD.GoCloudnet.ospwn
BitDefenderThetaGen:NN.ZexaF.34100.1JW@a4hbLIr
Invinceaheuristic
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.f4e7f2f72c43fd2e
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Glupteba
AviraTR/AD.GoCloudnet.ospwn
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.AntiAV
ArcabitTrojan.Generic.D28DA5BE
ZoneAlarmTrojan.Win32.AntiAV.cwau
AhnLab-V3Trojan/Win32.MalPe.R328278
Acronissuspicious
VBA32BScope.Trojan.AET.281105
Ad-AwareTrojan.GenericKD.42837438
MalwarebytesTrojan.MalPack.GS
PandaTrj/Agent.FUM
ESET-NOD32a variant of Win32/Kryptik.HBVX
TencentWin32.Trojan.Antiav.Efat
SentinelOneDFI – Malicious PE
FortinetW32/GenKryptik.HBUR!tr
WebrootW32.Trojan.Gen
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Anti.07a

How to remove Trojan.Win32.AntiAV.cwau?

Trojan.Win32.AntiAV.cwau removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment