Fake Trojan

Trojan:Win32/FakeFolder!pz removal guide

Malware Removal

The Trojan:Win32/FakeFolder!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FakeFolder!pz virus can do?

  • Sample contains Overlay data
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Operates on local firewall’s policies and settings

How to determine Trojan:Win32/FakeFolder!pz?


File Info:

name: D60A55CE7A357EE8B078.mlw
path: /opt/CAPEv2/storage/binaries/a9fff087b568556f1250c7daba4d54111b8e4679ae43387c503e15ad9296c207
crc32: DC3CAC66
md5: d60a55ce7a357ee8b078cbe7df9ab330
sha1: e80c3cda77904d1c6dfa9b733dd7127d187ea29a
sha256: a9fff087b568556f1250c7daba4d54111b8e4679ae43387c503e15ad9296c207
sha512: 21a3caf78c62b30d28b9038401527dd059c7662b5803e4a241cb659a7a0505b22de2b13127a0914dce2b0e43fd3f42fe6323443e53325d7e99e23ed5d942d59a
ssdeep: 768:k/510m+cd5rHemPXkqUEphjVuvios1rPr4adL0NqlJMU60+ppQ1TTGfL/U7:kRevcdcQjosnvnZ6LQ1E/K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3F3E5132BC9AA97EE100838166F1A342252DE3221D5B59BDF57F4DA3E3DCC179073A6
sha3_384: 183f3fe8fca8610dc53c78a8f621c4695b6a24ae4fcb68b89ef2c6ed8acf77143d93645a8cff62cf224a7635010a9bec
ep_bytes: 5589e56aff68e4b54000684859400064
timestamp: 1998-06-13 21:15:16

Version Info:

0: [No Data]

Trojan:Win32/FakeFolder!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94923
CAT-QuickHealWorm.Duptwux.A4
SkyhighBehavesLike.Win32.Backdoor.cz
McAfeeBackDoor-FAI
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.LolBot.Win32.288
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 001cef961 )
K7GWTrojan ( 001cef961 )
BitDefenderThetaGen:NN.ZexaF.36804.jyX@aaQ3bidi
VirITBackdoor.Win32.LolBot.RO
SymantecW32.Virut.CF
ESET-NOD32a variant of Win32/Agent.RTF
APEXMalicious
TrendMicro-HouseCallWORM_DUPTWU.SMIA
AvastWin32:Rbot-GQG [Trj]
ClamAVWin.Trojan.Lolbot-6804733-0
KasperskyBackdoor.Win32.LolBot.gen
BitDefenderTrojan.GenericKDZ.94923
NANO-AntivirusTrojan.Win32.LolBot.cqyqex
SUPERAntiSpywareTrojan.Agent/Gen-Lolbot
TencentTrojan.Win32.Agent.fk
EmsisoftTrojan.GenericKDZ.94923 (B)
BaiduWin32.Trojan.Agent.apt
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.DownLoader5.5739
VIPRETrojan.GenericKDZ.94923
TrendMicroWORM_DUPTWU.SMIA
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d60a55ce7a357ee8
SophosW32/Clovis-A
JiangminBackdoor/LolBot.ic
ALYacTrojan.GenericKDZ.94923
VaristW32/LolBot.A.gen!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Backdoor]/Win32.LolBot
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/FakeFolder!pz
XcitiumBackdoor.Win32.LolBot.GB@48x7ig
ArcabitTrojan.Generic.D172CB
ZoneAlarmBackdoor.Win32.LolBot.gen
GDataWin32.Worm.Ganelp.A
CynetMalicious (score: 100)
VBA32BScope.Worm.Duptwux
GoogleDetected
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Win32.FakeFolder.ak (CLASSIC)
YandexTrojan.GenAsa!pzhHdHqL0kI
IkarusTrojan-Ransom.ZedoPoo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rbot.GQG!tr
AVGWin32:Rbot-GQG [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Lolbot.a3f537be

How to remove Trojan:Win32/FakeFolder!pz?

Trojan:Win32/FakeFolder!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment