Fake Trojan

Should I remove “Trojan.FakeAntivirus.Gen”?

Malware Removal

The Trojan.FakeAntivirus.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeAntivirus.Gen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.FakeAntivirus.Gen?


File Info:

crc32: C2748EE9
md5: 3d95c34ad10691f9433b291e3e734653
name: 3D95C34AD10691F9433B291E3E734653.mlw
sha1: 794ee8359edfe32036bcb3a626e1cc12213a1277
sha256: 4cafc719c444fd72e8a781b34b414173ffe39fdd16ce29a0b709d2ac7bd1903f
sha512: 97e152e4f3a98eaed4fba494f8d41571970e38ddcdfd6f2043a33e17adff2cdd33f69ecd21cbcb9fc28b74d86d609fba4f700632e6a66e33a1810be9f8b94820
ssdeep: 6144:kdd46nwmwIyJTmFoMi96AIR0UwMYmYJyML/yaNwYG:KT7y8a6AIR0UwMYmYJyML/yaNwYG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Alexander Roshal 1993-2009
InternalName: WinRAR
FileVersion: 3.90.0
CompanyName: Alexander Roshal
ProductName: WinRAR
FileDescription: WinRAR archiver
OriginalFilename: WinRAR.exe
Translation: 0x0000 0x0000

Trojan.FakeAntivirus.Gen also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0021faa71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.FakeAntivirus.Gen
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.940698
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.68fbd97f
K7GWTrojan ( 0021faa71 )
Cybereasonmalicious.ad1069
CyrenW32/Zbot.CK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LIT
APEXMalicious
AvastWin32:MalOb-ID [Cryp]
KasperskyTrojan-Ransom.Win32.Blocker.hebn
BitDefenderTrojan.FakeAntivirus.Gen
NANO-AntivirusTrojan.Win32.Crypted.efxdqy
MicroWorld-eScanTrojan.FakeAntivirus.Gen
TencentWin32.Trojan.Blocker.Lner
Ad-AwareTrojan.FakeAntivirus.Gen
SophosML/PE-A + Mal/EncPk-WX
ComodoMalware@#2rho9bd8mf2kk
F-SecureTrojan.TR/Crypt.XPACK.Gen
BitDefenderThetaGen:NN.ZexaF.34690.2H0@ay1Agxni
VIPRETrojan.Win32.Jorik.smid (v)
TrendMicroTSPY_ZBOT.SMYX
McAfee-GW-EditionPWS-Zbot.gen.axh
FireEyeGeneric.mg.3d95c34ad10691f9
EmsisoftTrojan.FakeAntivirus.Gen (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Malware
MicrosoftTrojan:Win32/Dynamer!ac
AegisLabTrojan.Win32.Blocker.j!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.hebn
GDataTrojan.FakeAntivirus.Gen
AhnLab-V3Spyware/Win32.Zbot.R118486
Acronissuspicious
McAfeePWS-Zbot.gen.axh
MAXmalware (ai score=99)
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.IStartSurf
PandaTrj/Banker.JJG
TrendMicro-HouseCallTSPY_ZBOT.SMYX
RisingRansom.Blocker!8.12A (C64:YzY0Ok2KKTEc7Gu6)
IkarusTrojan-Dropper.Agent
FortinetW32/Kryptik.HZ!tr
AVGWin32:MalOb-ID [Cryp]
Paloaltogeneric.ml

How to remove Trojan.FakeAntivirus.Gen?

Trojan.FakeAntivirus.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment