Fake

What is “FakeAV.100”?

Malware Removal

The FakeAV.100 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAV.100 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine FakeAV.100?


File Info:

name: 4B56DF7A03DA2F6165D1.mlw
path: /opt/CAPEv2/storage/binaries/75f0d0f902b9334b5a8967cb4ca79c67c7691bcb75da4c417bc5a8b3de7edbef
crc32: 0CA828F3
md5: 4b56df7a03da2f6165d1f69cf7c74d6d
sha1: 071221e6390f8b27f06610049405ad06d1e25be2
sha256: 75f0d0f902b9334b5a8967cb4ca79c67c7691bcb75da4c417bc5a8b3de7edbef
sha512: 5d71ff5f97a005ec7667ffa8a7575ddefacad53e6b4a38f47c2e53831b0694feebab90c01295c3a0adcdbf2f6d1a1744a957b5853856f55e268c20bc2f273b17
ssdeep: 49152:bbWt7uAmCVzu2okeztGhgs2VvjgI8pnO1Eh2:ba6AMiefs2VLgI8pn32
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156B512209F5A7608E012ACF87574D3A3AB55028FD2EB4D52D263FB4412A9CF5CBBD0E5
sha3_384: f788cc013113e644843ac5d50e941651da4a8fc8eb9216eb444d9708267300305e2beb04e614b1f498db0e5cd7064712
ep_bytes: bafe000000bfbb0000002bda8bf7bb66
timestamp: 1970-01-01 05:07:47

Version Info:

CompanyName: procter and gamble company
FileVersion: 1.2
FileDescription: best shampoo in the world
InternalName: head and shoulders
LegalCopyright: trademark
LegalTrademarks: Copyright
OriginalFilename: nono
ProductName: head and shoulders
ProductVersion: 1.2
Translation: 0x0409 0x04e4

FakeAV.100 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop5.32568
MicroWorld-eScanGen:Variant.FakeAV.100
FireEyeGeneric.mg.4b56df7a03da2f61
ALYacGen:Variant.FakeAV.100
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.a03da2
BitDefenderThetaGen:NN.ZexaF.34742.ms3@aevd2Fai
CyrenW32/FakeAlert.UJ.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AIFB
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.FakeAV.100
NANO-AntivirusTrojan.Win32.TDSS.dabsye
SUPERAntiSpywareTrojan.Agent/Gen-FakeProtector
AvastWin32:FakeAV-DHV [Trj]
Ad-AwareGen:Variant.FakeAV.100
SophosML/PE-A + Mal/FakeAV-RM
ComodoTrojWare.Win32.Kryptik.AGIL@4p3mbb
McAfee-GW-EditionFakeAV-PJ.gen.at
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.FakeAV.100 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.FakeAV.100
AviraTR/TDSS.Gen2
MAXmalware (ai score=83)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.FakeAV.100
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
McAfeeFakeAV-PJ.gen.at
RisingTrojan.Generic@AI.98 (RDML:DRFJ0rqX0QVHRcQ9N9LHgw)
YandexTrojan.Agent!oT1IBRpjgr8
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik!tr
AVGWin32:FakeAV-DHV [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove FakeAV.100?

FakeAV.100 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment