Trojan

Trojan:Win32/Antavmu!pz (file analysis)

Malware Removal

The Trojan:Win32/Antavmu!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Antavmu!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Antavmu!pz?


File Info:

name: 98DBA9E93B0E07DE8029.mlw
path: /opt/CAPEv2/storage/binaries/7a07b750256f53c49010f92bee86392b7891947023acc3fd50313065a0782ab8
crc32: C0E3E567
md5: 98dba9e93b0e07de8029041199a300e9
sha1: 4174519af971598750cb83768300e045c1877ddf
sha256: 7a07b750256f53c49010f92bee86392b7891947023acc3fd50313065a0782ab8
sha512: fe1dd24847d950ae71f38626dd096b8a73b82ea940b94a413dac35e7eb6bec8e8637c9c21279d2006cc5f04a7775505e570cf72799f1d672bc65c4c7f108e0bc
ssdeep: 1536:hbGbefmMAXo3L7afK5QPqfhVWbdsmA+RjPFLC+e5hP0ZGUGf2g:h6beLqqfafNPqfcxA+HFshPOg
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T139739F22F9D0C430F45481B29D3D6E73EE3DAA64065793E79BD4F4A9CDB41D09A0B22B
sha3_384: 59a4491618c5881ee720383d296fad2214e82df3060c412daf96d1db96fd725133bef2b51d69015f40d5a0c21e458ee5
ep_bytes: a11bf14000c1e002a31ff14000526a00
timestamp: 2011-01-11 01:44:56

Version Info:

0: [No Data]

Trojan:Win32/Antavmu!pz also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Siggen8.42052
MicroWorld-eScanGen:Trojan.FileInfector.eGW@aKDb32o
ClamAVWin.Malware.Poison-10016370-0
CAT-QuickHealTrojan.AntavmuPMF.S31541431
SkyhighBehavesLike.Win32.Dropper.lh
McAfeePWS-OnlineGames.kz
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.FileInfector.eGW@aKDb32o
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001f4e2b1 )
K7GWTrojan ( 001f4e2b1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.FileInfector.EC4F1B
BitDefenderThetaAI:Packer.2D4DD5B71E
VirITTrojan.Win32.Generic.ABFQ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/KillFiles.NEH
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Trojan.FileInfector.eGW@aKDb32o
NANO-AntivirusTrojan.Win32.Antavmu.dhwgp
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Win32.Antavmu.b (CLASSIC)
EmsisoftGen:Trojan.FileInfector.eGW@aKDb32o (B)
F-SecureTrojan.TR/Antavmu.doena
ZillyaTrojan.KillFiles.Win32.39551
SophosMal/Antavmu-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.hrpwg
GoogleDetected
AviraTR/Antavmu.doena
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Antavmu
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.KillFiles.NEH@4qfvz0
MicrosoftTrojan:Win32/Antavmu!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.FileInfector.eGW@aKDb32o
VaristW32/Antavmu.D.gen!Eldorado
AhnLab-V3Trojan/Win32.Antavmu.R25058
VBA32BScope.Trojan.Downloader
TACHYONTrojan/W32.Antavmu.74752.E
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Agent.mgr
YandexTrojan.GenAsa!mLg/yf6hjK0
IkarusTrojan.Antavmu
MaxSecureTrojan.Malware.3411146.susgen
FortinetW32/KillFiles.NEH!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.af9715
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Antavmu!pz?

Trojan:Win32/Antavmu!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment