Trojan

Trojan.Win32.AntiAV.czie information

Malware Removal

The Trojan.Win32.AntiAV.czie is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.AntiAV.czie virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Slovenian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.AntiAV.czie?


File Info:

crc32: 9401E4F8
md5: 7689f5dde53833922581644ad73cba11
name: 7689F5DDE53833922581644AD73CBA11.mlw
sha1: ebd6566ac69bf3a55b0d83891e7a34fa096b5572
sha256: c339a2dfaf9d163cf0a421ce4f5342b3822b1628947e34e8be0eec1106f4ce62
sha512: 66597466b79f1293f4852024b57d8b76515d0c057801ec1488d2ce57024caef1c90355e5fe8ac14081803f0d87eaf560913fe4c682cd7d50b0eb2b08fc68ab04
ssdeep: 98304:8oiLbuOk+0uyY4qv5p/IGeNjrp+Gdsq37y72R8TV2laz9cW6MrR3z0zrPb8eYWQ:8nuO/yaQrx+xze5c2znW1Y0CUYg+Cai
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: reboud.exe
Product: 1.7.6
FileVersions: 1.0.5.4
LegalCo: Copyri (C) 2019, patron
Translation: 0x0439 0x00fa

Trojan.Win32.AntiAV.czie also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35848643
FireEyeGeneric.mg.7689f5dde5383392
McAfeeArtemis!7689F5DDE538
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005752ad1 )
BitDefenderTrojan.GenericKD.35848643
K7GWTrojan ( 005752ad1 )
Cybereasonmalicious.ac69bf
CyrenW32/Trojan.YJOS-9091
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BotX-gen [Trj]
KasperskyTrojan.Win32.AntiAV.czie
AlibabaTrojan:Win32/AntiAV.cab13fea
Ad-AwareTrojan.GenericKD.35848643
EmsisoftTrojan.GenericKD.35848643 (B)
F-SecureTrojan.TR/AD.GoCloudnet.bxbma
DrWebTrojan.Siggen11.56423
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/AD.GoCloudnet.bxbma
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Ymacco.AAA7
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Bandit
ZoneAlarmTrojan.Win32.AntiAV.czie
GDataTrojan.GenericKD.35848643
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R360167
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34700.@pGfa8ZjHbhc
ALYacTrojan.GenericKD.35848643
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIKI
TencentWin32.Trojan.Kryptik.Ahyn
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
FortinetW32/Kryptik.HFSR!tr
WebrootW32.Trojan.Gen
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Anti.24d

How to remove Trojan.Win32.AntiAV.czie?

Trojan.Win32.AntiAV.czie removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment