Fake

Should I remove “FakeAV.102”?

Malware Removal

The FakeAV.102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAV.102 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the shellcode get eip malware family
  • Attempts to identify installed analysis tools by registry key
  • Detects VirtualBox through the presence of a registry key
  • Enumerates physical drives
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine FakeAV.102?


File Info:

name: C2C319B2891E0A3B65F4.mlw
path: /opt/CAPEv2/storage/binaries/747ddf20436bf99cb7cdedfc87742a53b137a025c830e5265e7de2ae1c93c323
crc32: 70544E0C
md5: c2c319b2891e0a3b65f4316bfa311f13
sha1: 2d2f4e417ff447fd6cac86cc4275ec1fb3492f5f
sha256: 747ddf20436bf99cb7cdedfc87742a53b137a025c830e5265e7de2ae1c93c323
sha512: 13eb929d0559b2eba8de820664504fbad4631f0904e3626f384e37c3f71005770618407fea9fbf5f2f10bcd365b21ccfedb8cc26099c9310757f68e9ce7647d3
ssdeep: 12288:W48oQSGhy6IWlDdtnmtgtxSt5NDSOGPgAlddLRPBL3mgtC93DhP9amczywLj9c/u:LyTDXmtgSDpGVdLWgw1PKLJdt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12905011925876D06D4A838FCF6C274A2A36F0C27475AB12966717E360735AEBFEC130D
sha3_384: 0088d68234f03eb14246caa178768da63dbb7b3aaad2ff9ad67dd90cc2ee531dfe56efbe8c205a43afb79f8faee9e3f2
ep_bytes: 8bcc81f9f98a00007f198bc9fcb853cd
timestamp: 2009-12-30 13:50:19

Version Info:

0: [No Data]

FakeAV.102 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Simda.lJiP
AVGWin32:MalOb-IJ [Cryp]
tehtrisGeneric.Malware
DrWebTrojan.Rodricter.55
MicroWorld-eScanGen:Variant.FakeAV.102
FireEyeGeneric.mg.c2c319b2891e0a3b
CAT-QuickHealPWS.Simda.A
SkyhighBehavesLike.Win32.Generic.cc
McAfeeBackDoor-FBAQ!C2C319B2891E
MalwarebytesGeneric.Malware/Suspicious
ZillyaBackdoor.Simda.Win32.580
SangforSuspicious.Win32.Save.a
K7AntiVirusBackdoor ( 0040f53a1 )
AlibabaBackdoor:Win32/Simda.7ceaf92e
K7GWBackdoor ( 0040f53a1 )
Cybereasonmalicious.2891e0
BitDefenderThetaGen:NN.ZexaF.36802.ZKW@aKGWzEhc
VirITBackdoor.Win32.Generic.CGWC
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Simda.B
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Simda-277
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.FakeAV.102
NANO-AntivirusTrojan.Win32.Simda.brqnxl
AvastWin32:MalOb-IJ [Cryp]
RisingBackdoor.Simda!8.2D9 (TFE:1:TjopqluQwKV)
EmsisoftGen:Variant.FakeAV.102 (B)
F-SecureTrojan.TR/ATRAPS.Gen
VIPREGen:Variant.FakeAV.102
TrendMicroTROJ_SPNR.14E713
Trapminemalicious.high.ml.score
SophosMal/Encpk-ADD
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Simda.su
WebrootW32.Rogue.Gen
VaristW32/Simda.T.gen!Eldorado
AviraTR/ATRAPS.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Simda
KingsoftWin32.Trojan.Generic.a
MicrosoftBackdoor:Win32/Simda.A
XcitiumBackdoor.Win32.Simda.QAN@4unw94
ArcabitTrojan.FakeAV.102
ViRobotBackdoor.Win32.Simda.847360
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.FakeAV.102
GoogleDetected
VBA32SScope.Trojan.Simda.01718
ALYacGen:Variant.FakeAV.102
TACHYONBackdoor/W32.Simda.847360.B
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.14E713
YandexTrojan.Simda!26tVUYRZH8Q
IkarusBackdoor.Win32.Simda
MaxSecureTrojan.Malware.5501285.susgen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan:Win/Simda.B

How to remove FakeAV.102?

FakeAV.102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment