Trojan

About “Trojan.Win32.AntiAV.czdm” infection

Malware Removal

The Trojan.Win32.AntiAV.czdm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.AntiAV.czdm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.AntiAV.czdm?


File Info:

crc32: A7A90B69
md5: dd62d89adbf40ce20307f4abf81a12db
name: DD62D89ADBF40CE20307F4ABF81A12DB.mlw
sha1: 4aacd29388c3d34d95657c4dbfdd0b7e48983aaf
sha256: 736c4eb31f180f91da66e031edd07a09587da5130b914f77c22eb6513b4461cd
sha512: ebd797b383996e4380b267ac287f5eac96def7530cf18880d7b4dbd54f1183d84e9836d19d16520a1b7f19901ec719044df2d373177ab8d0b5eef0bcb38f20ac
ssdeep: 98304:yZr8RSYZB712+g4uWSpKt8Bw0c1U1flBfy8OxNdLj285fdlcKxH5ra7oKD0I8Rq:u8/fENfw/+flBmBNVt50v8vrr7/
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019, matrix
InternalName: reboot.exe
FileVersion: 1.0.5.4
ProductVersion: 1.7.6
Translation: 0x0841 0x04bb

Trojan.Win32.AntiAV.czdm also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35745267
FireEyeGeneric.mg.dd62d89adbf40ce2
McAfeeArtemis!DD62D89ADBF4
CylanceUnsafe
AegisLabTrojan.Win32.AntiAV.4!c
SangforMalware
K7AntiVirusTrojan ( 00574b9f1 )
BitDefenderTrojan.GenericKD.35745267
K7GWTrojan ( 00574b9f1 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Trojan.WAOY-7442
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Bunitu-9811454-0
KasperskyTrojan.Win32.AntiAV.czdm
AlibabaTrojan:Win32/AntiAV.45ab10dd
Ad-AwareTrojan.GenericKD.35745267
SophosMal/Generic-S
F-SecureTrojan.TR/AD.GoCloudnet.lawlm
DrWebTrojan.Siggen11.55605
TrendMicroTrojanSpy.Win32.ANTIAV.USMANLG20
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.lawlm
MAXmalware (ai score=88)
KingsoftWin32.Troj.Antiav.Cz.(kcloud)
MicrosoftTrojan:Win32/Coroxy.MR!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2216DF3
ZoneAlarmTrojan.Win32.AntiAV.czdm
GDataTrojan.GenericKD.35745267
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R358090
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34700.@pKfauj0Gwf
ALYacTrojan.GenericKD.35745267
VBA32BScope.Exploit.Shellcode
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIGQ
TrendMicro-HouseCallTrojanSpy.Win32.ANTIAV.USMANLG20
RisingTrojan.Ransom.GlobeImposter!1.AF70 (TFE:5:bYXJg1YG3DR)
YandexTrojan.AntiAV!9L3jE1OLBLw
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.388c3d
AvastWin32:DropperX-gen [Drp]
Qihoo-360Win32/Trojan.Anti.5a0

How to remove Trojan.Win32.AntiAV.czdm?

Trojan.Win32.AntiAV.czdm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment