Fake

FakeAlert.78 removal tips

Malware Removal

The FakeAlert.78 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAlert.78 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine FakeAlert.78?


File Info:

name: B2FB46C7C47C88F4415C.mlw
path: /opt/CAPEv2/storage/binaries/9cfae54aeb4f1f7579a1c03726e2878235d0de86acdbd9d6eb441c819747ae37
crc32: 558E741E
md5: b2fb46c7c47c88f4415cd9b80c6fa84a
sha1: d4d7b7d73810bb3930fadcbb0d3857dd94f035ec
sha256: 9cfae54aeb4f1f7579a1c03726e2878235d0de86acdbd9d6eb441c819747ae37
sha512: a7009b8deb8e2d5ea14e4e11192666771390c21db27c7b108c23bd57f5d21849e65868eeb5fc9b801fc303d205b9129f8d1d96e4cd6ccf273b35ba8326a8f9e2
ssdeep: 12288:EaRC2CEJbEEA9ukJdZPRvbOQk3P9rGy0Oj2:Ea+EJb/A9rJDZvbgVR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17F84F121E9B684A5F7D2C5B854F5F3902B7B5F741B432EC2A759F436183AFE87420222
sha3_384: 521574567964c39d6ddaef8fa60c35e16473eb22f652594bb173b67cf629d88b36e6e3f2cb1db621f8daa99ed1f18ba7
ep_bytes: 55909060909c90ba0000400081c20008
timestamp: 1977-08-15 23:32:18

Version Info:

0: [No Data]

FakeAlert.78 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.FakeAlert.78
CAT-QuickHealFraudTool.Security
McAfeeFakeAV-SecurityTool.iu
MalwarebytesMalware.AI.2652623335
VIPREGen:Variant.FakeAlert.78
SangforSuspicious.Win32.Save.ins
K7AntiVirusSpyware ( 005068aa1 )
K7GWSpyware ( 005068aa1 )
Cybereasonmalicious.7c47c8
CyrenW32/FakeAlert.OL.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.NGV
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Hoax.Win32.BdaReader.gen
BitDefenderGen:Variant.FakeAlert.78
NANO-AntivirusTrojan.Win32.Inject.cfnun
SUPERAntiSpywareTrojan.Agent/Gen-FakeSecurity
AvastWin32:Downloader-GWL [Adw]
TencentMalware.Win32.Gencirc.10bea859
TACHYONTrojan/W32.FakeAV.397312.M
SophosMal/FakeAV-CB
F-SecureTrojan.TR/Winwebsec.A.4345
DrWebTrojan.Inject.52584
ZillyaTrojan.FakeAV.Win32.114413
TrendMicroTROJ_FAKEAV.SMUC
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b2fb46c7c47c88f4
EmsisoftGen:Variant.FakeAlert.78 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.FakeAlert.78
JiangminTrojan/Fakeav.sch
AviraTR/Winwebsec.A.4345
Antiy-AVLHackTool[Hoax]/Win32.BdaReader
XcitiumTrojWare.Win32.Kryptik.NGW@3zv209
ArcabitTrojan.FakeAlert.78
ViRobotTrojan.Win32.A.FakeAv.397313
ZoneAlarmHEUR:Hoax.Win32.BdaReader.gen
MicrosoftRogue:Win32/Winwebsec
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R4559
BitDefenderThetaAI:Packer.6E57412521
ALYacGen:Variant.FakeAlert.78
MAXmalware (ai score=89)
VBA32SScope.Trojan.ExpProc.01
Cylanceunsafe
PandaTrj/Resdec.c
TrendMicro-HouseCallTROJ_FAKEAV.SMUC
RisingRansom.Foreign!8.292 (TFE:3:Ge0otlb2tkP)
YandexTrojan.Winwebsec!Lq3u59fPqoY
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PackFakeAV.HL!tr
AVGWin32:Downloader-GWL [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove FakeAlert.78?

FakeAlert.78 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment