Fake Trojan

About “Trojan:Win32/FakeFolder!pz” infection

Malware Removal

The Trojan:Win32/FakeFolder!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FakeFolder!pz virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/FakeFolder!pz?


File Info:

name: D438A5AF0BF7ADBD9229.mlw
path: /opt/CAPEv2/storage/binaries/48409a9d37d240f3ea865b57b7d81c05d28e01612e3f67c5359dc74a62e5d3fe
crc32: 252F427A
md5: d438a5af0bf7adbd92295690d2dccd49
sha1: c5697a23ec9ce798d4ae17b762601d1c20d8d77c
sha256: 48409a9d37d240f3ea865b57b7d81c05d28e01612e3f67c5359dc74a62e5d3fe
sha512: 32549c0c5c910221d33e9e14d3bee34fe8d07b9744cf412ca2e33e7c1cf7f3a09866cb3ad8f8c4d246e231407f971304682a4ec5464d8dd86257eb8bf874bd4d
ssdeep: 24576:mG2s/vZn2WTiFYCcQj/unPKa6oyzqxjvZvW:Jp26yVzqBvU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119057D53B3D7D0B2DF6626F3D6B49376193AB834173C89CB7390282EE8906C16A35359
sha3_384: f4e196b4e6ecea475b6b8eafe369e740a0e4f83d39d7bf7996a05204c39f7b69b405a9302d42407c34fcf2f517b598a1
ep_bytes: e8505e0000e989feffffcccccc568b44
timestamp: 2019-11-24 04:49:56

Version Info:

0: [No Data]

Trojan:Win32/FakeFolder!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.AHRun.4!c
MicroWorld-eScanGeneric.AutoHotKey.Agent.A.A7F446A4
FireEyeGeneric.AutoHotKey.Agent.A.A7F446A4
CAT-QuickHealPUA.AgentPMF.S24861111
SkyhighBehavesLike.Win32.Trojan.ch
ALYacGeneric.AutoHotKey.Agent.A.A7F446A4
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0057c4f51 )
BitDefenderGeneric.AutoHotKey.Agent.A.A7F446A4
K7GWTrojan ( 0057c4f51 )
ArcabitGeneric.AutoHotKey.Agent.A.A7F446A4
VirITTrojan.Win32.Generic.CDD
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.AHK.G suspicious
APEXMalicious
ClamAVWin.Malware.Misc-9950733-0
KasperskyTrojan.Win32.AHRun.gen
AlibabaTrojan:Win32/AHRun.48ecac0c
NANO-AntivirusTrojan.Win32.AHRun.jykttz
SophosTroj/AutoHK-N
F-SecureHeuristic.HEUR/AGEN.1319416
VIPREGeneric.AutoHotKey.Agent.A.A7F446A4
TrendMicroTROJ_GEN.R002C0PH723
EmsisoftGeneric.AutoHotKey.Agent.A.A7F446A4 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=85)
GoogleDetected
AviraHEUR/AGEN.1319416
VaristW32/FakeFolder.T.gen!Eldorado
MicrosoftTrojan:Win32/FakeFolder!pz
ZoneAlarmTrojan.Win32.AHRun.gen
GDataGeneric.AutoHotKey.Agent.A.A7F446A4
CynetMalicious (score: 100)
McAfeeTrojan-FUCG!D438A5AF0BF7
TACHYONTrojan/W32.Agent.824832.CC
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PH723
TencentTrojan.Win32.Agent.kb
IkarusPUA.AHK
FortinetRiskware/FakeFolder
AVGFileRepMalware [Misc]
AvastFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/FakeFolder!pz?

Trojan:Win32/FakeFolder!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment