Fake Trojan

Win32/TrojanDownloader.FakeAlert.AVM (file analysis)

Malware Removal

The Win32/TrojanDownloader.FakeAlert.AVM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.FakeAlert.AVM virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/TrojanDownloader.FakeAlert.AVM?


File Info:

name: 917147EEA11468A2EB64.mlw
path: /opt/CAPEv2/storage/binaries/54c4dec8d62447fe0b8846dec7556d2cf5b1158ff4bd6528b6e1d5c4c50d2f3d
crc32: 7D22022A
md5: 917147eea11468a2eb64e76284dddcc1
sha1: c9ee2f54216518755e39c704813e350cd4591b97
sha256: 54c4dec8d62447fe0b8846dec7556d2cf5b1158ff4bd6528b6e1d5c4c50d2f3d
sha512: 364ef342beafc9904703fee18f3acc3e65d94296088bfd6c040779df1d496dcc696ae3dbcce20172ec25a510e7a8ecf3aa20469ca1651f8ad54df07671a07c1b
ssdeep: 49152:j8Yl/kLYjAFjYtalkMyXh/ZMlqFxp73ooGBHI+ruP3A5GhOoT8NXadkMG1hdAK+Z:wspMqnhIHVruP3Ld81hCHC/zZP+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196469F29EAE20032CD53217AAB5F950073249C072119CB567ECCF3947FB6A749676FE8
sha3_384: aa4f6a106088ec2130f188f18856007a0d3b2a6bc2b1b0bb965a496b416138e27d625fbaea21f0ca22c6516bc53515b6
ep_bytes: e8fe830000e978feffff6a0c6870b342
timestamp: 2010-01-30 17:08:15

Version Info:

0: [No Data]

Win32/TrojanDownloader.FakeAlert.AVM also known as:

LionicTrojan.Win32.Cosmu.4!c
MicroWorld-eScanGen:Heur.Mint.Zard.39
FireEyeGeneric.mg.917147eea11468a2
CAT-QuickHealTrojan.GenericRI.S30115175
McAfeeGenericRXUX-ZQ!917147EEA114
Cylanceunsafe
ZillyaDownloader.FakeAlert.Win32.23264
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanDownloader:Win32/Cosmu.2b4fc877
K7GWTrojan-Downloader ( 0055e3da1 )
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderThetaGen:NN.ZexaF.36196.@t0@aWezpqhi
CyrenW32/FakeAlert.KI.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.FakeAlert.AVM
APEXMalicious
ClamAVWin.Malware.Generickdz-9943099-0
KasperskyTrojan.Win32.Cosmu.lof
BitDefenderGen:Heur.Mint.Zard.39
NANO-AntivirusTrojan.Win32.Cosmu.jublrr
AvastWin32:WormX-gen [Wrm]
TencentTrojan.Win32.Cosmu.hk
SophosTroj/FakeRean-O
F-SecureHeuristic.HEUR/AGEN.1363180
DrWebTrojan.DownLoad1.64284
VIPREGen:Heur.Mint.Zard.39
TrendMicroTROJ_GEN.R002C0DEL23
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Heur.Mint.Zard.39 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.10B47DD
JiangminTrojan/Cosmu.ect
AviraHEUR/AGEN.1363180
Antiy-AVLTrojan[Downloader]/Win32.FakeAlert
ArcabitTrojan.Mint.Zard.39
ZoneAlarmTrojan.Win32.Cosmu.lof
MicrosoftRogue:Win32/FakeRean
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Cosmu.R546350
Acronissuspicious
VBA32Trojan.Cosmu
ALYacGen:Heur.Mint.Zard.39
MAXmalware (ai score=81)
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R002C0DEL23
RisingAdware.FakeRean!8.1340B (TFE:5:w11Rnd04uVQ)
IkarusTrojan-Downloader.Win32.FakeRean
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Cosmu.KN!tr
AVGWin32:WormX-gen [Wrm]
Cybereasonmalicious.421651
DeepInstinctMALICIOUS

How to remove Win32/TrojanDownloader.FakeAlert.AVM?

Win32/TrojanDownloader.FakeAlert.AVM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment