Trojan

Should I remove “Trojan:Win32/Antavmu.D”?

Malware Removal

The Trojan:Win32/Antavmu.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Antavmu.D virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Antavmu.D?


File Info:

crc32: 7160547D
md5: 1ecf837a42bfa07ec0176a7c3614598a
name: 1ECF837A42BFA07EC0176A7C3614598A.mlw
sha1: fadad0c9852a2322367a086a0433f86603afd20f
sha256: 264180ca50c009df08c406494204b53d9e64d0acb2f74ce12667593603ba3a43
sha512: 8a10cc628eeca1b109553839e29d0963222b9529362ba3255ad5a49d7564ae0bcfa7402800be7fd2fbc90b817d234c6e7b02a25e2dc45845ed0a7ee76e8d9867
ssdeep: 1536:zmui7gzxBwW6R+7X/8qL90dqYAolOf0c3guoFY5umiB8GMGlZ5G:zmZkwWum0qLLTolOf0FF+uFN5G
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Antavmu.D also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.FileInfector.eGW@aiJEZzn
FireEyeGeneric.mg.1ecf837a42bfa07e
ALYacGen:Trojan.FileInfector.eGW@aiJEZzn
CylanceUnsafe
VIPRETrojan.Win32.Antavmu.d (v)
SangforMalware
K7AntiVirusTrojan ( 001f4e2b1 )
BitDefenderGen:Trojan.FileInfector.eGW@aiJEZzn
K7GWTrojan ( 001f4e2b1 )
CrowdStrikewin/malicious_confidence_90% (D)
TrendMicroTROJ_GEN.R06EC0DKI20
BitDefenderThetaAI:Packer.ED5D5D581E
CyrenW32/Antavmu.C.gen!Eldorado
SymantecTrojan.Dropper
APEXMalicious
ClamAVWin.Malware.Antavmu-9791257-0
KasperskyVirus.Win32.Lamer.gen
NANO-AntivirusTrojan.Win32.Drop.etmolw
Ad-AwareGen:Trojan.FileInfector.eGW@aiJEZzn
SophosMal/Antavmu-A
ComodoTrojWare.Win32.KillFiles.NEH@4qfvz0
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.MulDrop6.10374
InvinceaML/PE-A + Mal/Antavmu-A
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
EmsisoftGen:Trojan.FileInfector.eGW@aiJEZzn (B)
AviraTR/Crypt.ZPACK.Gen7
MicrosoftTrojan:Win32/Antavmu.D
ArcabitTrojan.FileInfector.ECA2F2
ZoneAlarmVirus.Win32.Lamer.gen
GDataGen:Trojan.FileInfector.eGW@aiJEZzn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Antavmu.R25058
Acronissuspicious
McAfeeArtemis!1ECF837A42BF
MAXmalware (ai score=88)
VBA32BScope.Trojan.Downloader
MalwarebytesVirus.Injector
PandaGeneric Suspicious
ESET-NOD32a variant of Win32/KillFiles.NEH
TrendMicro-HouseCallTROJ_GEN.R06EC0DKI20
RisingTrojan.Win32.Antavmu.d (CLASSIC)
YandexTrojan.GenAsa!mLg/yf6hjK0
SentinelOneStatic AI – Malicious PE
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
Qihoo-360HEUR/QVM20.1.540F.Malware.Gen

How to remove Trojan:Win32/Antavmu.D?

Trojan:Win32/Antavmu.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment