Fake

FakeAlert.42 removal

Malware Removal

The FakeAlert.42 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAlert.42 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine FakeAlert.42?


File Info:

name: 5BE594CC0F98CC55103F.mlw
path: /opt/CAPEv2/storage/binaries/1e52ba3275c938fc8405ea4529d94683f76f78e9dd4d72e3995984f8077b755f
crc32: C98FECBE
md5: 5be594cc0f98cc55103f12e5617874d2
sha1: 09f1b499b11c7771e66fd368dea29a91ee0d243d
sha256: 1e52ba3275c938fc8405ea4529d94683f76f78e9dd4d72e3995984f8077b755f
sha512: 6db275d6c8d6508970a9e86bd80df63119047c7e60c358a39dc6a2e1e0ac6d229faefebab33239ef344ab7d74f53f653b180df2fade940484024c5d2f5304430
ssdeep: 24576:Q1gHoNkhRWd4dcdINhGFS9pC/kXXeoMjTt/Zt:PJm4ddNhh9Ck+d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1584523D67E811FF3C456013047F7AB22EE22AD6A62254A13BAC23F1F5C71669DC4217E
sha3_384: 9b88eb74b2f1756160d6fefd6035a1af7971f5b1036e329061c447c70a0c82a48f6457eb218ec3e73a1a98ac3f5dbee7
ep_bytes: 558becff15d410000150e878faffff8b
timestamp: 2000-06-19 10:24:00

Version Info:

Translation: 0x0409 0x04b0

FakeAlert.42 also known as:

BkavW32.FakeAv24QKA.Fam.Adware
LionicHacktool.Win32.Krap.x!c
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.19447
MicroWorld-eScanGen:Variant.FakeAlert.42
FireEyeGeneric.mg.5be594cc0f98cc55
CAT-QuickHealTrojan.FraudPack
ALYacGen:Variant.FakeAlert.42
CylanceUnsafe
VIPREGen:Variant.FakeAlert.42
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001d15eb1 )
AlibabaPacked:Win32/Kryptik.c8570339
K7GWTrojan ( 001d15eb1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/FakeAlert.IF.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.IGH
APEXMalicious
TrendMicro-HouseCallTROJ_FAKEAV.SMCG
ClamAVWin.Trojan.Fakesec-892
KasperskyPacked.Win32.Krap.ic
BitDefenderGen:Variant.FakeAlert.42
SUPERAntiSpywareTrojan.Agent/Gen-FakeShield
AvastWin32:MalOb-DO [Cryp]
TencentWin32.Packed.Krap.biuv
Ad-AwareGen:Variant.FakeAlert.42
EmsisoftGen:Variant.FakeAlert.42 (B)
ComodoPacked.Win32.Krap.~IC@2o95zx
TrendMicroTROJ_FAKEAV.SMCG
McAfee-GW-EditionFakeAV-SecurityTool.ab
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/FakeAV-EE
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmPacked.Win32.Krap.ic
GDataGen:Variant.FakeAlert.42
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R1621
McAfeeFakeAV-SecurityTool.ab
VBA32BScope.Trojan.Packed
RisingTrojan.Generic@AI.100 (RDML:2OrxExrbJJlKBz4tfkrYag)
YandexTrojan.Winwebsec.Gen!Pac.23
IkarusTrojan.Win32.Crypt
FortinetW32/Katusha.R!tr
AVGWin32:MalOb-DO [Cryp]
PandaTrj/Genetic.gen

How to remove FakeAlert.42?

FakeAlert.42 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment