Trojan

Trojan:Win32/Antavmu!pz removal guide

Malware Removal

The Trojan:Win32/Antavmu!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Antavmu!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Antavmu!pz?


File Info:

name: CFBDB6F9B708BC5F2513.mlw
path: /opt/CAPEv2/storage/binaries/a769a9971bbff0602dd30db433300c6b6dcef0dc05c240a5a8f04cf38fbc9400
crc32: 15D00533
md5: cfbdb6f9b708bc5f251326702b894932
sha1: 9ed584f86ca9cf4262b2dc918cf4c48a9a288cb8
sha256: a769a9971bbff0602dd30db433300c6b6dcef0dc05c240a5a8f04cf38fbc9400
sha512: 7ebe439bdb118824f959ddc55d4b748f367f60bb28c19135bb4ce2911a2ca9860fa87f805fc0636534f91794025a073a4b3060047ce8068aedd70f0afcac9b75
ssdeep: 1536:zvUaySa+bHSOR6POQA8AkqUhMb2nuy5wgIP0CSJ+5yLB8GMGlZ5G:zv6wHn6mGdqU7uy5w9WMyLN5G
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19583AF51B8F0D430E44585B6897D7E73EE3FAE60070762B793D4A5A98FF1060A90B26B
sha3_384: c72fa87142de06e78116882958f845ed57afe0064e5fe2bf124aab6871297abc23190a0bb49efaabde29d2fd6d728575
ep_bytes: eb1066623a432b2b484f4f4b90e92811
timestamp: 2011-02-04 23:50:58

Version Info:

0: [No Data]

Trojan:Win32/Antavmu!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.FileInfector.eGW@aiJEZzn
FireEyeGeneric.mg.cfbdb6f9b708bc5f
CAT-QuickHealTrojan.AntavmuPMF.S19778283
SkyhighBehavesLike.Win32.Dropper.lh
ALYacGen:Trojan.FileInfector.eGW@aiJEZzn
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.FileInfector.eGW@aiJEZzn
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001f4e2b1 )
K7GWTrojan ( 001f4e2b1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.AFFA
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/KillFiles.NEH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Antavmu-9791257-0
KasperskyTrojan.Win32.KillFiles.dobe
BitDefenderGen:Trojan.FileInfector.eGW@aiJEZzn
NANO-AntivirusTrojan.Win32.MlwGen.dglxhu
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Killfiles.wa
TACHYONTrojan/W32.Agent.81408.AAO
SophosMal/Antavmu-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.MulDrop6.10374
ZillyaTrojan.KillFiles.Win32.30210
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.FileInfector.eGW@aiJEZzn (B)
IkarusTrojan.Win32.Antavmu
GDataGen:Trojan.FileInfector.eGW@aiJEZzn
JiangminTrojanDownloader.NSIS.ff
WebrootW32.Infector
VaristW32/Antavmu.C.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Win32.Antavmu
Kingsoftmalware.kb.a.993
XcitiumTrojWare.Win32.KillFiles.NEH@4qfvz0
ArcabitTrojan.FileInfector.ECA2F2
ZoneAlarmTrojan.Win32.KillFiles.dobe
MicrosoftTrojan:Win32/Antavmu!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Antavmu.R25058
Acronissuspicious
McAfeeGenericRXHL-ZT!CFBDB6F9B708
MAXmalware (ai score=80)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Win32.Antavmu.d (CLASSIC)
YandexTrojan.GenAsa!mLg/yf6hjK0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1207282.susgen
FortinetW32/Antavmu.JWS!tr
BitDefenderThetaAI:Packer.ED5D5D581E
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.86ca9c
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Antavmu!pz?

Trojan:Win32/Antavmu!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment