Fake

Should I remove “Win32:FakeAV-EXP [Trj]”?

Malware Removal

The Win32:FakeAV-EXP [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeAV-EXP [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32:FakeAV-EXP [Trj]?


File Info:

name: 88F40911D577ED5FB3AD.mlw
path: /opt/CAPEv2/storage/binaries/489edaaa5dda796c0b3d2fe8be12bb77c94a58ff7bb8f2156b0da481cdf08026
crc32: 3168949C
md5: 88f40911d577ed5fb3ad8d67f356e4a6
sha1: 0146632137a8e3cfd9c9f95d1cde39d86579ed7f
sha256: 489edaaa5dda796c0b3d2fe8be12bb77c94a58ff7bb8f2156b0da481cdf08026
sha512: 296dd8606c3a87609567761e1ef01a4b3c59d03316ecbd00b6c52cf98aadbf267000952bc4f44fc44b460ba05a2c48c563428d5fa1d07709493d7a9cfdb89af2
ssdeep: 6144:SwdcbBWggww0S7s0uKZxfiymppZMnSWagpDyAA/nfkfr77:BdcbBO0Sw09ZEmnS5gpD4Mfv7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1006422894B45BCFFC1BF41B23366448783E8C20068112B7EFAA9A51DAF7C5C1A585FA5
sha3_384: 2d87b766b1a9351bbcc5068c74005a6d89d78b0f06500caa13467d05f64f6946352e2925ff0c0baa8c3ebd759428ba50
ep_bytes: 8d0424662d00f0724fb8603040008bcc
timestamp: 2006-04-18 09:18:53

Version Info:

0: [No Data]

Win32:FakeAV-EXP [Trj] also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.88f40911d577ed5f
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeeBackDoor-FBFW!88F40911D577
CylanceUnsafe
VIPRETrojan.Win32.Zbot.smb (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f61b1 )
BitDefenderTrojan.VIZ.Gen.1
K7GWTrojan ( 0040f61b1 )
Cybereasonmalicious.1d577e
BaiduWin32.Trojan.Kryptik.fx
VirITTrojan.Win32.Generic.CMBM
CyrenW32/SuspPack.FP.gen!Eldorado
SymantecPacked.Generic.432
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
ClamAVWin.Trojan.Tepfer-61
KasperskyTrojan-Spy.Win32.Zbot.psnc
NANO-AntivirusTrojan.Win32.Zbot.ctmttz
RisingTrojan.Spy.Win32.Zbot.gxd (CLASSIC)
Ad-AwareTrojan.VIZ.Gen.1
EmsisoftTrojan.VIZ.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.BLA@52cguh
DrWebTrojan.PWS.PandaENT.4379
ZillyaTrojan.Zbot.Win32.145664
TrendMicroTROJ_KRYPTK.SMN6
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosML/PE-A + Troj/FakeAV-GWD
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.enwg
AviraTR/Urausy.5145615
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.430D1E
MicrosoftPWS:Win32/Zbot!GO
SUPERAntiSpywareTrojan.Agent/Gen-FakeAV
GDataTrojan.VIZ.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fareit.R82830
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34182.sqW@aqTObgii
ALYacTrojan.VIZ.Gen.1
TACHYONTrojan-Spy/W32.ZBot.308224.AOE
VBA32Heur.Trojan.Hlux
MalwarebytesTrojan.MalPack.CD
PandaTrj/Tepfer.B
TrendMicro-HouseCallTROJ_KRYPTK.SMN6
TencentWin32.Trojan-spy.Zbot.Eeho
YandexTrojan.GenAsa!08jQe2OI5RM
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BDPK!tr
AVGWin32:FakeAV-EXP [Trj]
AvastWin32:FakeAV-EXP [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32:FakeAV-EXP [Trj]?

Win32:FakeAV-EXP [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment