Trojan

Trojan:Win32/Antavmu!pz (file analysis)

Malware Removal

The Trojan:Win32/Antavmu!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Antavmu!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid

How to determine Trojan:Win32/Antavmu!pz?


File Info:

name: 57877E2437C7F647BCDA.mlw
path: /opt/CAPEv2/storage/binaries/744f8fc1e31847d691496d6c8e1c3249579043f892408d300b88c8b8c9c05b0e
crc32: 2C0F4729
md5: 57877e2437c7f647bcda8af803d2b4c7
sha1: f6b4a0f2129b62fd7717cabd74c86ebc8953fa51
sha256: 744f8fc1e31847d691496d6c8e1c3249579043f892408d300b88c8b8c9c05b0e
sha512: c9135ad5c0f973d5d073c6bd2232c5691a2aa4f72e67063ef8c355d714ab1903fb329c9017813a54943ac086d32d8cb2b4c976ffef59e006cd9575d33afa63aa
ssdeep: 1536:sMp+MGWez2yTFAWHwabD5P9n55OoMGMGHX:sMAMGWpyXwaXnDOs
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T182438F13B890C035F44088F45D7D4EB3EE3FEE600656926B9391E5A5CEF15A0FA0A36B
sha3_384: eec0c8b73594677add4519bdda00a0c0eec1eca600c07ddd8359585053b3049801fe8a491868825288902dfb4d336eeb
ep_bytes: eb1066623a432b2b484f4f4b90e928b1
timestamp: 2010-11-03 14:11:29

Version Info:

0: [No Data]

Trojan:Win32/Antavmu!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Antavmu.lZ2a
DrWebTrojan.MulDrop2.40169
MicroWorld-eScanGen:Trojan.FileInfector.dGW@a4t5tzk
SkyhighDropper-FAH!57877E2437C7
McAfeeDropper-FAH!57877E2437C7
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Genome.Win32.208128
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Antavmu.f5d95e9d
K7GWTrojan ( 001f4e2b1 )
K7AntiVirusTrojan ( 001f4e2b1 )
BitDefenderThetaAI:Packer.AB54A0AF1E
VirITTrojan.Win32.MulDrop2.CHKZ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.ARJ
TrendMicro-HouseCallTROJ_GENOME_00000aa.TOMA
Paloaltogeneric.ml
KasperskyTrojan.Win32.Bingoml.aifr
BitDefenderGen:Trojan.FileInfector.dGW@a4t5tzk
NANO-AntivirusTrojan.Win32.TrjGen.oojgv
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Bingoml.Mqil
EmsisoftGen:Trojan.FileInfector.dGW@a4t5tzk (B)
F-SecureMalware.W32/Ildirim
VIPREGen:Trojan.FileInfector.dGW@a4t5tzk
FireEyeGen:Trojan.FileInfector.dGW@a4t5tzk
SophosTroj/Antavmu-B
MAXmalware (ai score=100)
JiangminTrojan/Genome.bjiy
WebrootW32.Trojan.Gen
GoogleDetected
AviraW32/Ildirim
VaristW32/Ildirim.A.gen!Eldorado
Antiy-AVLTrojan/Win32.Genome
Kingsoftmalware.kb.a.881
MicrosoftTrojan:Win32/Antavmu!pz
XcitiumWorm.Win32.Ildirim.K@54rvnk
ArcabitTrojan.FileInfector.E66DE7
ZoneAlarmTrojan.Win32.Bingoml.aifr
GDataGen:Trojan.FileInfector.dGW@a4t5tzk
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Antavmu.R25058
VBA32Trojan.Genome.ac
ALYacGen:Trojan.FileInfector.dGW@a4t5tzk
TACHYONWorm/W32.FileInfector.58880.B
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.Antavmu!8.2A5 (TFE:5:naZFA6oKvKG)
YandexTrojan.GenAsa!LNq9xkeYFQw
IkarusTrojan.Win32.Genome
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Genome.AC!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Killfiles

How to remove Trojan:Win32/Antavmu!pz?

Trojan:Win32/Antavmu!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment