Trojan

Trojan.Win32.AntiAV.czjr removal tips

Malware Removal

The Trojan.Win32.AntiAV.czjr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.AntiAV.czjr virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.AntiAV.czjr?


File Info:

crc32: E12E1DA8
md5: 5b7c21d7256992bbb1b6f44e102ef5d0
name: 5B7C21D7256992BBB1B6F44E102EF5D0.mlw
sha1: 5ace5368f7fe5f4b87ff2d5bb68dcf46ccd0a11a
sha256: 329d00a9139afef791ad2c0648abc7b5481fdf7828a74de6d1b7168d83b70121
sha512: 4a5450ee12419b98f6ccab5c2ba0481b0f1fbd0194c1b5adff69eb6f9d97fb41924a60d8ff395bc1d450b2bf9405ab4082b8a0aae7834673782eae7620899ab6
ssdeep: 98304:urwaEi5wE2lb25K5Gc96vWtEDfZ8RfNUWYdEZ4GzPzOtyRxSieb1KWg0qC5uBOz:fi2bD5wvWy4fNO+gSzKgtAHNUTMlscC
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Product: 1.7.7
FileVersions: 1.0.5.2
LegalCo: Copyri (C) 2019, permudationz

Trojan.Win32.AntiAV.czjr also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35895933
FireEyeGeneric.mg.5b7c21d7256992bb
Qihoo-360Generic/HEUR/QVM11.1.351F.Malware.Gen
ALYacTrojan.GenericKD.35895933
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055a4081 )
BitDefenderTrojan.GenericKD.35895933
K7GWTrojan ( 0055a4081 )
Cybereasonmalicious.8f7fe5
BitDefenderThetaGen:NN.ZexaF.34700.@pGfa8u2vRoc
CyrenW32/Trojan.WZIC-1585
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan.Win32.AntiAV.czjr
AlibabaTrojan:Win32/AntiAV.0f7476c0
AegisLabTrojan.Win32.AntiAV.4!c
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
Ad-AwareTrojan.GenericKD.35895933
SophosMal/Generic-S
DrWebTrojan.Siggen11.56746
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
EmsisoftTrojan.GenericKD.35895933 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Convagent.af
AviraTR/AD.GoCloudnet.ctf
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Zenpack.MT!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D223BA7D
ZoneAlarmTrojan.Win32.AntiAV.czjr
GDataTrojan.GenericKD.35895933
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361113
Acronissuspicious
McAfeeGenericRXAA-AA!5B7C21D72569
VBA32Backdoor.Agent
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32Win32/RanumBot.J
TencentWin32.Trojan.Antiav.Sxou
IkarusTrojan.Win32.Ranumbot
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HGHW!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.AntiAV.czjr?

Trojan.Win32.AntiAV.czjr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment