Trojan

Trojan.Win32.AntiAV removal guide

Malware Removal

The Trojan.Win32.AntiAV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.AntiAV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Attempts to restart the guest VM
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system

How to determine Trojan.Win32.AntiAV?


File Info:

crc32: 059C6942
md5: dbdc04946fa3c9c7194da3e2ffd86523
name: DBDC04946FA3C9C7194DA3E2FFD86523.mlw
sha1: 9b34bff78d9591ecd3ca928c54cc02d97dd42c32
sha256: 6651e6156af086e120114fb83b10af8b07acac4b73998cf5758bb5fe17677bfc
sha512: 0a535dec2a86039a97fb9f77e5efecba52d730584cd9b4fb6caac4152462641bd9845a72a7d72ce6cd3ab33c278cd449ce99e4c4a1eb1871dfd2fb6f82a34f30
ssdeep: 98304:JbQ8+3bUd19MXPHYD4MoChE6bqc3OZaDreC3YMlPdo:Jc8+3boXUvC4MNE6bdzDeePC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVer: 2.0.9.29
FileV: 1.0.2.37
Translations: 0x0255 0x029d

Trojan.Win32.AntiAV also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44638661
FireEyeGeneric.mg.dbdc04946fa3c9c7
McAfeeTrojan-FSUC!DBDC04946FA3
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.GenericKD.44638661
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Glupteba.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.AntiAV.gen
ViRobotTrojan.Win32.Z.Ranumbot.3980288.A
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
Ad-AwareTrojan.GenericKD.44638661
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/AD.GoCloudnet.bys
DrWebTrojan.Siggen11.48398
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.wc
SophosMal/Generic-S
IkarusTrojan.Win32.Ranumbot
JiangminTrojan/Obfuscated.eakb
AviraTR/AD.GoCloudnet.bys
MAXmalware (ai score=80)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Ranumbot.RQ!MSR
GridinsoftTrojan.Win32.Packed.vb
ArcabitTrojan.Generic.D2A921C5
ZoneAlarmHEUR:Trojan.Win32.AntiAV.gen
GDataWin32.Trojan.PSE.E1MOMX
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.C4230338
BitDefenderThetaGen:NN.ZexaF.34658.YtW@aOsy6ucO
ALYacTrojan.Agent.Ranumbot
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HHRT
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HHRC!tr
WebrootW32.Malware.Gen
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.Win32.AntiAV?

Trojan.Win32.AntiAV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment