Fake

Should I remove “Win32:FakeAlert-ZH [Trj]”?

Malware Removal

The Win32:FakeAlert-ZH [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeAlert-ZH [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32:FakeAlert-ZH [Trj]?


File Info:

name: 05F5FAF6107A488595E0.mlw
path: /opt/CAPEv2/storage/binaries/8d5ae092f3f8c6c2bd59663467ee3feba4061fb75f01ed322c1c9b088f413e4d
crc32: DFDED94C
md5: 05f5faf6107a488595e0898a3addcfdd
sha1: 0b4f461f6a7920823f5eb4c4ba54c684b67fca7a
sha256: 8d5ae092f3f8c6c2bd59663467ee3feba4061fb75f01ed322c1c9b088f413e4d
sha512: 5b23bff2771506ca782fc511317686dffb96f5860d8afcf5d1b40ef9877f9db4b10a95047c642d4b3c65f60836678301bb7d26140fc191209f11a43e4ea99024
ssdeep: 1536:+/jNp0f636TtnThBn+ChhLRb5jIs25LP6e8H:iRSf636TRThB+2b5mPwH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AD53DF1EC0F1A891E9F5D27251F2F2428631B9711A3E067E02051DBFA9FD6448E9CBB7
sha3_384: 651ed95c22e06e2d5267f3723e27e557e8a35a16b7275e5bc0ce726ef72d3264fa3dcb759bc22b05bc33e957a840c1ce
ep_bytes: 558bec83c48ce831090000a1e8cf4100
timestamp: 2009-02-26 05:28:57

Version Info:

Comments:
CompanyName: ComponentOne LLC
FileDescription: DrWeb For Windows r 2011
FileVersion: 5.0.572.1152
InternalName: Dr.Web for Windows
LegalCopyright: Copyright (C) jn DoctorWeb, Ltd., 1992-2011
LegalTrademarks:
OriginalFilename: hRFile ProtectorS v2011 oy.exe
ProductName: Dr.Web for Windows
ProductVersion: 5.0.572.1152
Translation: 0x0419 0x04e3

Win32:FakeAlert-ZH [Trj] also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.CodecPack.a!c
AVGWin32:FakeAlert-ZH [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zbot.10
FireEyeGeneric.mg.05f5faf6107a4885
CAT-QuickHealTrojan.Renos.LX
ALYacGen:Variant.Zbot.10
CylanceUnsafe
VIPREGen:Variant.Zbot.10
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 002056d81 )
AlibabaTrojanDownloader:Win32/CodecPack.a33af2c9
K7GWTrojan ( 002056d81 )
Cybereasonmalicious.6107a4
VirITTrojan.Win32.CodecPack.AIEY
CyrenW32/FakeAlert.KN.gen!Eldorado
SymantecTrojan.FakeAV!gen48
ESET-NOD32Win32/TrojanDownloader.FakeAlert.AQI
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.FakeAV-14042
KasperskyTrojan-Downloader.Win32.CodecPack.aiey
BitDefenderGen:Variant.Zbot.10
NANO-AntivirusTrojan.Win32.CodecPack.faojhf
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[DrWeb]
AvastWin32:FakeAlert-ZH [Trj]
TencentMalware.Win32.Gencirc.10c33f8c
Ad-AwareGen:Variant.Zbot.10
SophosML/PE-A + Mal/FakeAV-IZ
ComodoTrojWare.Win32.Kryptik.VL@2qgufe
DrWebTrojan.Siggen2.21503
ZillyaTrojan.FakeAV.Win32.818
TrendMicroTROJ_FAKEAV.SM1C
McAfee-GW-EditionDownloader-CEW.x
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zbot.10 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.CodecPack.caj
WebrootW32.Malware.Downloader
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.14
KingsoftWin32.TrojDownloader.CodecPack.ai.(kcloud)
MicrosoftTrojanDownloader:Win32/Renos.PT
ArcabitTrojan.Zbot.10
ViRobotTrojan.Win32.FakeAV.64512
GDataGen:Variant.Zbot.10
GoogleDetected
AhnLab-V3Win-Trojan/Fakeav.64512.T
McAfeeDownloader-CEW.x
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTROJ_FAKEAV.SM1C
RisingDownloader.Renos!8.1D0 (TFE:2:aU1JrNZmBUF)
YandexTrojan.GenAsa!1j4z4zM4dXQ
IkarusTrojan-Downloader.Win32.CodecPack
MaxSecureTrojan.Malware.1669930.susgen
FortinetW32/Krypt.QKV!tr
BitDefenderThetaGen:NN.ZexaF.34646.dq0@ayESqEai
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:FakeAlert-ZH [Trj]?

Win32:FakeAlert-ZH [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment