Fake Trojan

What is “TrojanFakeAV.InfoArmor”?

Malware Removal

The TrojanFakeAV.InfoArmor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanFakeAV.InfoArmor virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the embedded pe malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanFakeAV.InfoArmor?


File Info:

name: BFA909B93A0675897B64.mlw
path: /opt/CAPEv2/storage/binaries/60ca2bcee0d8a5c5684efe3dfdfa6ead58d9fb48d25f2881eceea4a1c4f17078
crc32: 754E4C88
md5: bfa909b93a0675897b64c69f700fb447
sha1: c9a15d9ccba47e87b0c48d3fd37cb1810bee6c2a
sha256: 60ca2bcee0d8a5c5684efe3dfdfa6ead58d9fb48d25f2881eceea4a1c4f17078
sha512: a418b49ffd0180d90eecd534d12532b83d0e75597faef3f8cac0d26596a31a52fc0aa7f403eda5864be47fa0db77e3722d889d0cdf21a52f547cc23ddc352fba
ssdeep: 196608:UAzPZsCgJaDeW4oWXS0RJei22j8eHnwmeUYjALy1u9UCUQFGYI4Ma1t7pv:UOHgJaDeW4oW1b1I8wmNYjALyC/F1Y87
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CBA633D48D34E573F52A6DBBFF8369E971B2021A73284E97CE83DE9D3960E241342644
sha3_384: de168d2f228caaeb7e0f0218d0140562eb85b67e1e3d1d7761359dc8ce7575616d50c6bac3aafbc6d32e7d5c96c5d0ba
ep_bytes: 60be00c041008dbe0050feff5783cdff
timestamp: 2004-01-09 10:12:34

Version Info:

0: [No Data]

TrojanFakeAV.InfoArmor also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Infoarmor-2
SkyhighRDN/Generic.hbg
McAfeeArtemis!BFA909B93A06
AlibabaTrojan:Win32/fragment.ab7e333a
VirITTrojan.Win32.Generic.BVAL
SymantecTrojan.Gen.2
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.FakeAV.bovqbe
AvastWin32:Trojan-gen
RisingTrojan.Generic!8.C3 (CLOUD)
F-SecureHeuristic.HEUR/AGEN.1310418
DrWebTrojan.Fakealert.36884
ZillyaTrojan.InfoArmor.Win32.7
TrendMicroMal_MLWR-24
SophosMal/Generic-S
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Troj.Unknown.a
XcitiumMalware@#qm3subuaqr6h
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vigorf.A
VaristW32/Risk.WJAZ-2585
VBA32TrojanFakeAV.InfoArmor
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallMal_MLWR-24
TencentMalware.Win32.Gencirc.11b739d8
YandexTrojan.GenAsa!IyINLXFDfVM
IkarusTrojan.Agent
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Krap.C
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove TrojanFakeAV.InfoArmor?

TrojanFakeAV.InfoArmor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment