Threat Database Trojans Trojan.FakeAV.ADQ

Trojan.FakeAV.ADQ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,943
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: April 3, 2026
Last Seen: April 22, 2026
OS(es) Affected: Windows

The detection of Trojan.FakeAV.ADQ indicates that your system has been compromised by a malicious threat. This type of malware is designed to deceive users into believing their system is infected with viruses or other types of malware, when in fact the malware itself is the problem. It's essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.FakeAV.ADQ?

Trojan.FakeAV.ADQ is a type of Trojan horse malware that masquerades as a legitimate antivirus program. The name "FakeAV" suggests that it pretends to be an antivirus solution, but its true purpose is to compromise your system's security and potentially steal sensitive information. Trojan horses are known for their ability to disguise themselves as harmless or even beneficial programs, making them particularly dangerous.

How Trojan.FakeAV.ADQ Operates

Once installed on your system, Trojan.FakeAV.ADQ can operate in various ways to achieve its malicious goals. It may display fake alerts and warnings about supposed virus infections, attempting to convince you to purchase a fake antivirus solution or pay for unnecessary services. In some cases, it might also install additional malware or create backdoors for remote access, allowing attackers to control your system or steal your data.

Symptoms of Infection

Identifying the symptoms of a Trojan.FakeAV.ADQ infection can be challenging, as it often mimics legitimate antivirus software. However, some common signs include unexpected pop-ups or alerts about virus infections, slow system performance, or unfamiliar programs installed on your system. You might also notice that your browser settings have been altered or that you're being redirected to suspicious websites.

  • Unfamiliar programs or icons on your desktop or taskbar
  • Changes to your browser's homepage or search engine
  • Frequent pop-ups or alerts about supposed virus infections
  • Slow system performance or frequent crashes

How to Remove Trojan.FakeAV.ADQ

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.FakeAV.ADQ from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable antivirus tools, you can effectively remove this threat and protect your system from future infections. Remember to always be cautious when installing new software or clicking on links from unknown sources, as these are common ways for malware to spread. Stay vigilant and keep your system up to date with the latest security patches to minimize the risk of infection.

Analysis Report

General information

Family Name: Trojan.FakeAV.ADQ
Signature status: No Signature

Known Samples

MD5: 67661bdf4e4f3cabd300e776f785358f
SHA1: 245695b29409d751cf09e38a47ab54b75bfad7de
SHA256: 04D8F7258AB93A2EC9C18E14636B5D0D1FB6FA0AC7C82B29973D213473C57602
File Size: 18.43 KB, 18432 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 44
Potentially Malicious Blocks: 39
Whitelisted Blocks: 5
Unknown Blocks: 0

Visual Map

0 x x x 0 x 0 x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • FakeAV.ADQ

Files Modified

File Attributes
c:\users\user\appdata\roaming\microsoft\windows\wininit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ヷ깠퉒ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 垽깧퉒ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::windows initializer C:\Users\Nzepuelp\AppData\Roaming\Microsoft\Windows\wininit.exe RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe gߏ�R�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 꺢퉒ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 篚꺬퉒ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::windows initializer C:\Users\Nzepuelp\AppData\Roaming\Microsoft\Windows\wininit.exe RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Network Winsock2
  • WSAStartup
Service Control
  • OpenSCManager
  • OpenService
Network Winsock
  • freeaddrinfo
  • getaddrinfo
Network Icmp
  • IcmpCreateFile
  • IcmpSendEcho2Ex
Process Terminate
  • TerminateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

netsh.exe advfirewall firewall add rule name="Windows Initializer" dir=in action=allow program="c:\users\user\downloads\245695b29409d751cf09e38a47ab54b75bfad7de_0000018432" enable=yes
netsh.exe advfirewall firewall add rule name="P2P_UDP_4711" dir=in action=allow protocol=UDP localport=4711
C:\Users\Nzepuelp\AppData\Roaming\Microsoft\Windows\wininit.exe
cmd.exe /c ping 127.0.0.1 -n 3 > nul & del "c:\users\user\downloads\245695b29409d751cf09e38a47ab54b75bfad7de_0000018432"
netsh.exe advfirewall firewall add rule name="Windows Initializer" dir=in action=allow program="C:\Users\Nzepuelp\AppData\Roaming\Microsoft\Windows\wininit.exe" enable=yes
Show More
netsh.exe advfirewall firewall add rule name="P2P_UDP_4711" dir=in action=allow protocol=UDP localport=4711
C:\WINDOWS\SysWOW64\svchost.exe (NULL)
C:\WINDOWS\system32\PING.EXE ping 127.0.0.1 -n 3

Trending

Most Viewed

Loading...