Fake

What is “FakeAlert.93”?

Malware Removal

The FakeAlert.93 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAlert.93 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify user notification settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine FakeAlert.93?


File Info:

name: A52B2FE63ABBD05D51B0.mlw
path: /opt/CAPEv2/storage/binaries/cb6591b5f6db22e339aa57d3045edb529e24c410b9af96293660f8434bad9b27
crc32: 70284AC9
md5: a52b2fe63abbd05d51b09e21c4730c49
sha1: b0eaa924918564905c5ffd78ca8d6f608203240d
sha256: cb6591b5f6db22e339aa57d3045edb529e24c410b9af96293660f8434bad9b27
sha512: 66142372b84231b9c3f21c768e2665979a2b5dd38831da752975116976954ffa49426766c88d22bdf4bab13284ce0e102023c319f692b476be5f0a7ceecbe79d
ssdeep: 12288:P8B+d+iWpNoQaPAcGuYNDsljQY4uCxBduLg0yUf:AVT5TcGKlv4TduJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12D94F10074D85C11F4C2F9F81795C916C6689D0B8224FA9BAA78BE1FB5322E7FC54B4E
sha3_384: a9041f96db60bb31f0e6aae4228a5a2760c33ae47be86bbeadd7eb78e9bbeae43fa3d52510aea6b5864c4c07441373da
ep_bytes: 6a606838814100e871130000bf940000
timestamp: 2012-04-28 10:21:12

Version Info:

0: [No Data]

FakeAlert.93 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lIo2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.FakeAlert.93
FireEyeGeneric.mg.a52b2fe63abbd05d
CAT-QuickHealFraudTool.Security
McAfeeFakeAV-SecurityTool.eg
Cylanceunsafe
ZillyaTrojan.Agent.Win32.235510
SangforSuspicious.Win32.Save.ins
K7AntiVirusAdware ( 004cc2ec1 )
AlibabaTrojan:Win32/Katusha.d59c2c11
K7GWAdware ( 004cc2ec1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36744.AqW@aiV4!tni
SymantecTrojan.FakeAV!gen89
tehtrisGeneric.Malware
ESET-NOD32Win32/Adware.SystemSecurity.AK
APEXMalicious
ClamAVWin.Trojan.Fakeav-43893
KasperskyHEUR:Trojan.Win32.FakeAV.gen
BitDefenderGen:Variant.FakeAlert.93
NANO-AntivirusTrojan.Win32.FakeAV.covjwp
AvastWin32:FakeAlert-CLM [Trj]
TencentMalware.Win32.Gencirc.10b86ae5
TACHYONTrojan-Clicker/W32.Fakealert.425984.G
EmsisoftGen:Variant.FakeAlert.93 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen20.6881
VIPREGen:Variant.FakeAlert.93
TrendMicroTROJ_KRYPTIK.SM17
Trapminemalicious.high.ml.score
SophosMal/FakeAV-RP
IkarusTrojan.Win32.FakeAV
JiangminTrojan.Fakeav.dic
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/FakeAlert.TW.gen!Eldorado
Antiy-AVLTrojan[FakeAV]/Win32.Agent
KingsoftWin32.HeurC.KVM007.a
XcitiumTrojWare.Win32.Kryptik.AEZP@4oe579
ArcabitTrojan.FakeAlert.93
ViRobotTrojan.Win32.A.Agent.425984.I
ZoneAlarmHEUR:Trojan.Win32.FakeAV.gen
GDataGen:Variant.FakeAlert.93
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R24360
Acronissuspicious
VBA32BScope.TrojanFakeAV.Agent
ALYacGen:Variant.FakeAlert.93
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Resdec.c
TrendMicro-HouseCallTROJ_KRYPTIK.SM17
RisingTrojan.Generic@AI.100 (RDMK:VhNnHKFfpChSlaMmI+PwqQ)
YandexTrojan.GenAsa!tqJ/h3E0bZs
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GQEQ!tr
AVGWin32:FakeAlert-CLM [Trj]
Cybereasonmalicious.491856
DeepInstinctMALICIOUS

How to remove FakeAlert.93?

FakeAlert.93 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment