Threat Database Trojans Trojan.AntiVM.A

Trojan.AntiVM.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,781
Threat Level: 80 % (High)
Infected Computers: 9
First Seen: March 6, 2025
Last Seen: July 23, 2026
OS(es) Affected: Windows

The detection of Trojan.AntiVM.A on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to evade detection by traditional security measures, making it a significant concern for users. In this report, we will provide an overview of the threat, its operation, symptoms of infection, and steps to remove it from your system.

What Is Trojan.AntiVM.A?

Trojan.AntiVM.A is a type of Trojan horse malware that is designed to bypass virtual machine (VM) detection. Trojans are malicious programs that disguise themselves as legitimate software, allowing them to gain unauthorized access to a system. The ".AntiVM" suffix suggests that this particular threat is designed to evade detection by virtual machines, which are often used by security software to analyze and detect malware.

How Trojan.AntiVM.A Operates

Once installed on a system, Trojan.AntiVM.A can operate in various ways, depending on its intended purpose. It may be designed to steal sensitive information, such as login credentials or financial data, or to install additional malware on the system. It may also be used to create a backdoor, allowing remote access to the system by the attacker. The exact operation of Trojan.AntiVM.A will depend on the specific goals of the attacker and the design of the malware.

Symptoms of Infection

Systems infected with Trojan.AntiVM.A may exhibit a range of symptoms, including slow system performance, unexpected crashes, and unusual network activity. Users may also notice that their system is behaving erratically, such as displaying unusual error messages or warning alerts. In some cases, the malware may be designed to operate stealthily, making it difficult to detect without the use of specialized security software.

  • Unexplained changes to system settings or configuration
  • Appearance of unknown or suspicious programs or files
  • Increased network activity or unexpected data transfers
  • System crashes or freezes
  • Unusual error messages or warning alerts

How to Remove Trojan.AntiVM.A

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or suspicious files.
  3. Uninstall any suspicious programs or software that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the malware has been fully removed.

Conclusion

The detection of Trojan.AntiVM.A on your system is a serious security concern that requires immediate attention. By following the steps outlined in this report, you can help to remove the malware and prevent further damage to your system. It is essential to remain vigilant and to take proactive steps to protect your system from future threats, including keeping your operating system and security software up to date, using strong passwords, and avoiding suspicious downloads or links.

Analysis Report

General information

Family Name: Trojan.AntiVM.A
Signature status: No Signature

Known Samples

MD5: 5f0e8de0a0c19983da09551741fe0042
SHA1: 2def34387995327546e910241d2d8c1ff90a632b
SHA256: 4EB1361400E1941A8BEF96A1210359A036E35EA8A6996359E7700DB9A985D701
File Size: 345.52 KB, 345520 bytes
MD5: b19c27f87f5c5adc3b297f7b6ae9f0c9
SHA1: 80caa5d976e2dcdb7ccda5f1a0076e10788af062
SHA256: D663CB5CCCCD438DDF5B728BFD804079687406793030908BBF36A0CCD03C6663
File Size: 277.50 KB, 277504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Dr Mona Lisa
File Description Ignore Double Mouse Click
File Version 1.1.0.0
Internal Name IgnoreDoubleMouseClick.exe
Legal Copyright (C) 2025 Copyright by Dr.MonaLisa. All Rights Reserved.
Original Filename IgnoreDoubleMouseClick.exe
Product Name Ignore Double Mouse Click
Product Version 1.1.0.0

Digital Signatures

Signer Root Status
EE2.eu - Dr. Mona Lisa EE2.eu - Dr. Mona Lisa Self Signed

File Traits

  • fptable
  • No Version Info
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 938
Potentially Malicious Blocks: 1
Whitelisted Blocks: 933
Unknown Blocks: 4

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Agent.Gen.DTH

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 紡집ᾋǝ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
Show More
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Other Suspicious
  • SetWindowsHookEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c pause