Trojan

Trojan:Win32/Antavmu!pz removal tips

Malware Removal

The Trojan:Win32/Antavmu!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Antavmu!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Antavmu!pz?


File Info:

name: 1812D2FA0A2FEF7441D3.mlw
path: /opt/CAPEv2/storage/binaries/0a2c63ddf3f7354824bf53c2d4453af8b64938edcb83a5219c091b437df5f68c
crc32: 201F8DE0
md5: 1812d2fa0a2fef7441d37a9d95a4373e
sha1: e74b930b2207e868b1ed18881cc22cbfa696b6e9
sha256: 0a2c63ddf3f7354824bf53c2d4453af8b64938edcb83a5219c091b437df5f68c
sha512: e50c12132c49a5224350a080398c31c32da03da7a9e52c7c421d896f824736f8e47cd4554fcdcaebe76a85d1590e025b8c19909642766b63d494e320c492a78b
ssdeep: 1536:zvTWcksg0pOQA8AkqUhMb2nuy5wgIP0CSJ+5yjB8GMGlZ5G:zvqvL0oGdqU7uy5w9WMyjN5G
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14483B05178F0D430E44585B2897D7D73EE3FAA60075B65A793D0A298CFE11A0AE0F36B
sha3_384: cc6458c1fb521b18a4743547559c55710ab149756d5be6597d707541527589cd8512dc4659a2c643bcab343a7116d816
ep_bytes: eb1066623a432b2b484f4f4b90e92811
timestamp: 2011-02-04 23:50:58

Version Info:

0: [No Data]

Trojan:Win32/Antavmu!pz also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AntavmuPMF.S19778283
SkyhighBehavesLike.Win32.Dropper.lh
McAfeeGenericRXHL-ZT!1812D2FA0A2F
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.KillFiles.Win32.30029
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001f4e2b1 )
K7GWTrojan ( 001f4e2b1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.AFFA
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/KillFiles.NEH
APEXMalicious
ClamAVWin.Malware.Antavmu-9791257-0
KasperskyTrojan.Win32.KillFiles.dobe
BitDefenderGen:Trojan.FileInfector.eGW@aiJEZzn
NANO-AntivirusTrojan.Win32.MlwGen.dglwqu
MicroWorld-eScanGen:Trojan.FileInfector.eGW@aiJEZzn
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Killfiles.wa
TACHYONTrojan/W32.Agent.81408.AAO
EmsisoftGen:Trojan.FileInfector.eGW@aiJEZzn (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.MulDrop6.10374
VIPREGen:Trojan.FileInfector.eGW@aiJEZzn
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.1812d2fa0a2fef74
SophosMal/Antavmu-A
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.FileInfector.eGW@aiJEZzn
JiangminTrojanDownloader.NSIS.ff
WebrootW32.Infector
GoogleDetected
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Win32.Antavmu
XcitiumTrojWare.Win32.KillFiles.NEH@4qfvz0
ArcabitTrojan.FileInfector.ECA2F2
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmTrojan.Win32.KillFiles.dobe
MicrosoftTrojan:Win32/Antavmu!pz
VaristW32/Antavmu.C.gen!Eldorado
AhnLab-V3Trojan/Win32.Antavmu.R25058
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Trojan.FileInfector.eGW@aiJEZzn
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Win32.Antavmu.d (CLASSIC)
YandexTrojan.GenAsa!mLg/yf6hjK0
IkarusTrojan.Win32.Antavmu
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Antavmu.JWS!tr
BitDefenderThetaAI:Packer.ED5D5D581E
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.b2207e
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Antavmu!pz?

Trojan:Win32/Antavmu!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment