Trojan

Trojan.Win32.AntiAV.czeh removal guide

Malware Removal

The Trojan.Win32.AntiAV.czeh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.AntiAV.czeh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.AntiAV.czeh?


File Info:

crc32: 4C0CD116
md5: 203dbd1520b7d01b3d497ee01163cc85
name: 203DBD1520B7D01B3D497EE01163CC85.mlw
sha1: 78cbd34ceeba61822213f90dbd457c37e0b9a629
sha256: ae8fa3b5a31d3844159b3812cc7e6b3eae8d3b0f31933bb18809de745e291f8f
sha512: 9c73286040de6c2224f3397a9d7666ce04e62bcd66eb6125e5ea01287f1d05f64b872247c38ef09af56e1b04f53125d62b568ffd05d1cb9069f363dc864bd524
ssdeep: 98304:cngBrGZAct+3LDJGG1Ikcv3DyW4tT6/RUldvzHktnmnDrFL/Mt1+dWChHKw4uSe:OwrGyF3L/QPJtRUPprFG+hhqDyjsvjy
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019, matrix
InternalName: reboot.exe
FileVersion: 1.0.5.4
ProductVersion: 1.7.6
Translation: 0x0419 0x04e8

Trojan.Win32.AntiAV.czeh also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45047103
FireEyeGeneric.mg.203dbd1520b7d01b
ALYacTrojan.GenericKD.45047103
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00574db21 )
BitDefenderTrojan.GenericKD.45047103
K7GWTrojan ( 00574db21 )
Cybereasonmalicious.ceeba6
CyrenW32/Trojan.SZYZ-1822
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Generic-9811131-0
KasperskyTrojan.Win32.AntiAV.czeh
AlibabaTrojan:Win32/AntiAV.de2895bf
RisingTrojan.Ransom.GlobeImposter!1.AF70 (TFE:5:bYXJg1YG3DR)
Ad-AwareTrojan.GenericKD.45047103
EmsisoftTrojan.Crypt (A)
ComodoMalware@#qv5o0zdzutzh
F-SecureTrojan.TR/AD.GoCloudnet.grojy
DrWebTrojan.Siggen11.55727
TrendMicroTrojanSpy.Win32.ANTIAV.USMANLH20
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.grojy
MAXmalware (ai score=83)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Glupteba.NP!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2AF5D3F
ZoneAlarmTrojan.Win32.AntiAV.czeh
GDataTrojan.GenericKD.45047103
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R358738
Acronissuspicious
McAfeeGenericRXAA-AA!203DBD1520B7
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIHM
TrendMicro-HouseCallTrojanSpy.Win32.ANTIAV.USMANLH20
YandexTrojan.GenAsa!A3rOJaxYS2w
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34700.@pKfaCt8ssb
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.FBF5.Malware.Gen

How to remove Trojan.Win32.AntiAV.czeh?

Trojan.Win32.AntiAV.czeh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment