Fake Trojan

Trojan.FakeAv.ZW removal

Malware Removal

The Trojan.FakeAv.ZW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeAv.ZW virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.FakeAv.ZW?


File Info:

name: 4278CEB647ABD2BAA427.mlw
path: /opt/CAPEv2/storage/binaries/083b1173495bc99962661a0f24fe489206340a6a699ddeb1117c8752f261f46d
crc32: B9CC2C2A
md5: 4278ceb647abd2baa427f4f9cba0e4c6
sha1: 3620390aa5ab1cc41bded280625c1948490fcd1b
sha256: 083b1173495bc99962661a0f24fe489206340a6a699ddeb1117c8752f261f46d
sha512: 3546e08ef5fddd012457244790dada7d0bb1c5b30e2b013023734bbd3164b0f1487d3a868be274da5d1d7182256ea268e0d516bfe107434c7a1551e7d00a4cab
ssdeep: 49152:I+po0PXcDYdElurT31IvatpBckbgiM+JCG:IaPMDYdEI1gatpBvnJD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188A57D31B2A59433E673DB357C8B4E945C367E202964889B3FBC590C5E39B8178293B7
sha3_384: 62037b3978de72d4c65d23997e509d222e10e24835fc925c3c3c1779726cb30da6c88dff13b2c32ca647905c706fde91
ep_bytes: 558bec8b451050837d0c011bc04083e0
timestamp: 2003-09-05 11:35:31

Version Info:

0: [No Data]

Trojan.FakeAv.ZW also known as:

LionicTrojan.Win32.Generic.lrGb
MicroWorld-eScanTrojan.FakeAv.ZW
ClamAVWin.Trojan.FakeAV-3699
FireEyeGeneric.mg.4278ceb647abd2ba
McAfeeFakeAV-SecurityTool.ar
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.FraudPack.Win32.13477
SangforVirus.Win32.Save.a
AlibabaAdWare:Win32/FakeAV.48e5710d
Cybereasonmalicious.647abd
BitDefenderThetaGen:NN.ZelphiF.36250.cwW@a0KAwkg
VirITTrojan.Win32.Fakealert.NTV
CyrenW32/FakeAlert.EY.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.SecurityTool
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.FakeAv.ZW
NANO-AntivirusTrojan.Win32.FraudPack.bztwu
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.115d379b
TACHYONTrojan/W32.FraudPack.2133504
EmsisoftTrojan.FakeAv.ZW (B)
F-SecureWorm.WORM/Koobface.brx
DrWebTrojan.Fakealert.9303
VIPRETrojan.FakeAv.ZW
TrendMicroTROJ_FAKEAV.SMDI
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
Trapminemalicious.high.ml.score
SophosMal/FakeAV-DQ
SentinelOneStatic AI – Suspicious PE
GDataTrojan.FakeAv.ZW
JiangminTrojan/FraudPack.qqa
AviraWORM/Koobface.brx
Antiy-AVLTrojan/Win32.FraudPack
XcitiumWorm.Win32.Koobface.brx1@1n8q7u
ArcabitTrojan.FakeAv.ZW
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRogue:Win32/Winwebsec
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R9098
Acronissuspicious
VBA32Trojan.FraudPack
ALYacTrojan.FakeAv.ZW
MAXmalware (ai score=99)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_FAKEAV.SMDI
RisingAdware.Winwebsec!8.135E4 (TFE:5:Qzyn4mwHxFF)
YandexTrojan.GenAsa!TjO50VommMw
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/FAKEAV.SMDI!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.FakeAv.ZW?

Trojan.FakeAv.ZW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment