Trojan

About “Trojan:Win32/Antavmu!pz” infection

Malware Removal

The Trojan:Win32/Antavmu!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Antavmu!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Antavmu!pz?


File Info:

name: ED4C2E2718943D3C7D26.mlw
path: /opt/CAPEv2/storage/binaries/7c37e07b608c7a01235d3bed2bffbde539e5990f2501decb6d4b184f13b5bd77
crc32: 3F4709F5
md5: ed4c2e2718943d3c7d2664383174bb03
sha1: 2a695e55b949f2938f55c6e7fb1c9e6c291cb1d1
sha256: 7c37e07b608c7a01235d3bed2bffbde539e5990f2501decb6d4b184f13b5bd77
sha512: ca31294013da6ff121d027306d8824c7cf125ed97c87629ac8d67152a00bdec07a9d8af009cf19744859f7578735a434073335b5ca8fddb2a07d38131acadc85
ssdeep: 1536:hbK6B3YLsGjFk/K5QPqfhVWbdsmA+RjPFLC+e5hf0ZGUGf2g:hX3YLsGoNPqfcxA+HFshfOg
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F3739F62B9D0C434F04481B29D3D5E73BE3EEA540B5793F79BD4A5A8CDA41D09A0B32B
sha3_384: fafdc255c2c45fcb3e92ab5a6134ac1b3808cc001b69963b40a12b1e438180c166e04e676ec9f2a30cd5ab3e6ed0c534
ep_bytes: a11bf14000c1e002a31ff14000526a00
timestamp: 2011-01-11 01:44:56

Version Info:

0: [No Data]

Trojan:Win32/Antavmu!pz also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Siggen8.42052
MicroWorld-eScanGen:Trojan.FileInfector.eGW@aKDb32o
CAT-QuickHealTrojan.AntavmuPMF.S31541431
SkyhighBehavesLike.Win32.Dropper.lh
McAfeePWS-OnlineGames.kz
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001f4e2b1 )
K7GWTrojan ( 001f4e2b1 )
Cybereasonmalicious.5b949f
ArcabitTrojan.FileInfector.EC4F1B
BitDefenderThetaAI:Packer.2D4DD5B71E
VirITTrojan.Win32.Generic.ABFQ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/KillFiles.NEH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Poison-10016370-0
KasperskyVirus.DOS.Moctezuma.2416
BitDefenderGen:Trojan.FileInfector.eGW@aKDb32o
NANO-AntivirusTrojan.Win32.Antavmu.dhwgp
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Trojan.FileInfector.eGW@aKDb32o (B)
F-SecureTrojan.TR/Antavmu.doena
VIPREGen:Trojan.FileInfector.eGW@aKDb32o
SophosMal/Antavmu-A
IkarusTrojan.Win32.Antavmu
JiangminTrojan.Generic.hrpwg
VaristW32/Antavmu.D.gen!Eldorado
AviraTR/Antavmu.doena
Antiy-AVLTrojan/Win32.KillFiles
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.KillFiles.NEH@4qfvz0
MicrosoftTrojan:Win32/Antavmu!pz
ZoneAlarmUDS:Trojan.Win32.Generic
GDataGen:Trojan.FileInfector.eGW@aKDb32o
GoogleDetected
AhnLab-V3Trojan/Win32.Antavmu.R25058
ALYacGen:Trojan.FileInfector.eGW@aKDb32o
TACHYONTrojan/W32.Antavmu.74752.E
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Win32.Antavmu.b (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3411146.susgen
FortinetW32/KillFiles.NEH!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Antavmu!pz?

Trojan:Win32/Antavmu!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment