Trojan

Trojan:Win32/Antavmu!pz removal tips

Malware Removal

The Trojan:Win32/Antavmu!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Antavmu!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Antavmu!pz?


File Info:

name: 3B07A2648810C8715770.mlw
path: /opt/CAPEv2/storage/binaries/7bcea728baf7e13ca9335e2d6e8f101ea5e6f0cf344e3ca0dbb2221202ff9d5d
crc32: FF9C8C0E
md5: 3b07a2648810c871577095cd45fa1b46
sha1: 6530e72440acf570d0d3bf2fea3d4f7c7caad68c
sha256: 7bcea728baf7e13ca9335e2d6e8f101ea5e6f0cf344e3ca0dbb2221202ff9d5d
sha512: 61a1038672c64364e49930fc58b913a2176e17106a0edfda06686386871d30f8e85b78e2c5a2c5dd97de28b2b18e574be2bc08d38e3f294e0f571e2e3b780cbe
ssdeep: 1536:hbb9u/urTQWRK5QPqfhVWbdsmA+RjPFLC+e5hT0ZGUGf2g:h/9u8NPqfcxA+HFshTOg
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C673AF22B9D0C531F04085B25D3C6A73EE3E9A540A5793F75B94F5A8CEF1190EA0A32F
sha3_384: 3d155af19eb2d2942b8bac0f7db137251a46d9ef5f4555adb320bbb0bd47218efe55da689f069518da20fd0b0ce8ae02
ep_bytes: a11bf14000c1e002a31ff14000526a00
timestamp: 2011-01-11 01:44:56

Version Info:

0: [No Data]

Trojan:Win32/Antavmu!pz also known as:

BkavW32.AIDetectMalware
LionicVirus.DOS.Moctezuma.tnBC
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.FileInfector.eGW@aKDb32o
FireEyeGeneric.mg.3b07a2648810c871
CAT-QuickHealTrojan.AntavmuPMF.S31541431
SkyhighBehavesLike.Win32.Dropper.lh
ALYacGen:Trojan.FileInfector.eGW@aKDb32o
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001f4e2b1 )
AlibabaMalware:Win32/km_2242df.None
K7GWTrojan ( 001f4e2b1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.FileInfector.EC4F1B
BitDefenderThetaAI:Packer.2D4DD5B71E
VirITTrojan.Win32.Generic.ABFQ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KillFiles.NEH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Poison-10016370-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Trojan.FileInfector.eGW@aKDb32o
NANO-AntivirusTrojan.Win32.Antavmu.dhwgp
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Agent.mgr
TACHYONTrojan/W32.Antavmu.74752.E
EmsisoftGen:Trojan.FileInfector.eGW@aKDb32o (B)
F-SecureTrojan.TR/Antavmu.doena
DrWebTrojan.Siggen8.42052
VIPREGen:Trojan.FileInfector.eGW@aKDb32o
TrendMicroTROJ_GEN.R002C0DLT23
Trapminemalicious.high.ml.score
SophosMal/Antavmu-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.hrpwg
VaristW32/Antavmu.D.gen!Eldorado
AviraTR/Antavmu.doena
Antiy-AVLTrojan/Win32.Antavmu
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.KillFiles.NEH@4qfvz0
MicrosoftTrojan:Win32/Antavmu!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.FileInfector.eGW@aKDb32o
GoogleDetected
AhnLab-V3Trojan/Win32.Antavmu.R25058
McAfeePWS-OnlineGames.kz
MAXmalware (ai score=87)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLT23
RisingTrojan.Win32.Antavmu.b (CLASSIC)
YandexTrojan.GenAsa!mLg/yf6hjK0
IkarusTrojan.Antavmu
MaxSecureTrojan.Malware.3411146.susgen
FortinetW32/KillFiles.NEH!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.440acf
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Antavmu!pz?

Trojan:Win32/Antavmu!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment