Threat Database Trojans Trojan.FakeAV.ZD

Trojan.FakeAV.ZD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,754
Threat Level: 80 % (High)
Infected Computers: 8
First Seen: January 10, 2023
Last Seen: April 28, 2026
OS(es) Affected: Windows

The detection of Trojan.FakeAV.ZD on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.FakeAV.ZD?

Trojan.FakeAV.ZD is a type of malicious software that disguises itself as a legitimate program or application. The name "Trojan" refers to the fact that this malware uses deception to gain access to your system, much like the legendary Trojan Horse. The ".FakeAV" part of the name suggests that this malware may pose as anti-virus software or a security tool, aiming to trick users into installing or paying for fake protection.

How Trojan.FakeAV.ZD Operates

Once installed, Trojan.FakeAV.ZD can operate in various ways, depending on its intended purpose. It may attempt to steal sensitive information, such as login credentials, credit card numbers, or personal data. It can also use your computer as a botnet to spread spam, launch denial-of-service attacks, or engage in other malicious activities. Additionally, Trojan.FakeAV.ZD may try to download and install other malware or unwanted programs, further compromising your system's security.

Symptoms of Infection

Identifying the symptoms of a Trojan.FakeAV.ZD infection can be challenging, as this malware often disguises itself as legitimate software. However, you may notice some unusual behavior on your computer, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also receive fake alerts or warnings about non-existent security threats, attempting to scare you into paying for fake protection or installing additional malware.

How to Remove Trojan.FakeAV.ZD

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Trojan.FakeAV.ZD and any related malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.FakeAV.ZD from your system requires careful attention to detail and a thorough approach. By following the steps outlined above, you can help ensure the complete removal of this malware and prevent future infections. It is essential to remain vigilant and keep your anti-virus software up-to-date to protect your computer and personal data from emerging threats. Remember to always be cautious when installing new software or clicking on links from unknown sources, as these can often be vectors for malware infections.

Analysis Report

General information

Family Name: Trojan.FakeAV.ZD
Signature status: Hash Mismatch

Known Samples

MD5: f17f17c9d126c6a46ba6889c1174bf01
SHA1: 1124044caf3895a26a9346760218e601b2434389
SHA256: D8C77967FC08921EA9BFDAED34884F18C7E041AD415A191881F6CD4E9734EDA7
File Size: 2.49 MB, 2490397 bytes
MD5: d70e2e59516ccdce9aab3a5a00991993
SHA1: ec86a11d4ffb5dfbc6bb7f1b92afa5a61f7e423f
SHA256: C72E8F4C68709CFC625B2DF7EA6AB18A303868042B678500EFE8B569A6B8ED12
File Size: 1.18 MB, 1179648 bytes
MD5: 076c0df2fe4ea2a1c2d102d53d7c364f
SHA1: 47e01f1b03fd4eb3e29fc1d2b5fc7fd4d684ba8f
SHA256: E67412FF642CDD23B090B54FEF5560E73C1F1DD9909EDE98C7CA814BE68854F6
File Size: 1.52 MB, 1519520 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name CrystalIDEA Software
File Description AnyToISO Converter
File Version
  • 3.2.0.408
  • 2.5.2.140
Internal Name anytoiso.exe
Legal Copyright
  • 2008-2011 (c) CrystalIDEA Software. All rights reserved.
  • 2008-20010 (c) CrystalIDEA Software. All rights reserved.
Original Filename anytoiso.exe
Product Name AnyToISO Converter
Product Version
  • 3.2.0.408
  • 2.5.2.140

Digital Signatures

Signer Root Status
crystalidea.com Certum Level III CA Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 4,882
Potentially Malicious Blocks: 317
Whitelisted Blocks: 2,533
Unknown Blocks: 2,032

Visual Map

? 0 0 0 ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? ? ? 0 ? ? ? 0 0 ? ? 0 ? x 0 ? 0 0 ? 0 ? ? ? ? 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? ? ? ? ? ? 0 0 0 0 ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 ? 0 ? ? 0 0 ? ? ? ? 0 0 ? 0 0 ? 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 ? ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? 0 0 ? ? ? ? ? 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x ? ? ? ? ? 0 ? 0 ? 0 0 ? ? ? 0 ? ? ? 0 ? 0 ? 0 0 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 ? ? 0 x 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 ? 0 ? 0 0 ? ? ? 0 ? ? ? 0 x x x 0 x x 0 x 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 ? ? ? ? ? ? x x 0 0 0 0 ? 0 ? ? ? ? 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x 0 ? ? ? ? ? ? ? ? ? 1 ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 0 0 ? ? ? 0 x x x ? x x x 0 x x x ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 ? 0 0 ? ? 0 0 ? ? 0 0 0 ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? 0 0 0 ? ? ? ? 0 0 ? ? 0 ? 0 ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? 0 0 ? ? 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 ? ? 0 ? ? 0 0 0 0 0 0 ? x ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsq8fb0.tmp\langdll.dll Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...