Fake

About “FakeAV.102” infection

Malware Removal

The FakeAV.102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAV.102 virus can do?

  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine FakeAV.102?


File Info:

name: 1892237D3221CFC53E1C.mlw
path: /opt/CAPEv2/storage/binaries/51c59f720ac6be7f9a0f1e12a3ac28ebd363e5dc2f473d5a0dd9f42ff25094d6
crc32: 82DDEFA9
md5: 1892237d3221cfc53e1ce1362c3068e4
sha1: 6bd091f1e158bf4a0fd49da21f6f7e434d42f8e1
sha256: 51c59f720ac6be7f9a0f1e12a3ac28ebd363e5dc2f473d5a0dd9f42ff25094d6
sha512: 7652722b693daadf487cce02da85b0c8a2733cdb72f95ff8c81cd5b228c279d3307daf84a76e787a8146a44669a108cb48f06f895d84a103fa657aa16b1213ba
ssdeep: 384:YXEvbFPX38clyTTiPGHfIwxW+M2DbArVTmt/ArfAKBqzaLUGLGh03C6:YUDlMhksfWTubArwtWsGAoGi7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107823A06BAE4CBC4DCC9067C2E63E775183955F1085F59ADEBD4C6CB149B312B8EC12A
sha3_384: af906327d72125f11bb612bfef672134e65098311b3412e75ef9586c2b6a311c638938bb4f682dbe1557c5dec96f749d
ep_bytes: 5589e531c031c9fce816000000ac30d0
timestamp: 2008-06-17 22:58:16

Version Info:

0: [No Data]

FakeAV.102 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.HLLM.Siggen.3983
MicroWorld-eScanGen:Variant.FakeAV.102
SkyhighBehavesLike.Win32.Generic.lh
McAfeeGenericRXCD-HW!1892237D3221
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059d46c1 )
K7GWTrojan ( 0059d46c1 )
Cybereasonmalicious.1e158b
ArcabitTrojan.FakeAV.102
BitDefenderThetaAI:Packer.6C843A3A1C
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Lover.B
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Lover-9776445-0
KasperskyEmail-Worm.Win32.Lover.a
BitDefenderGen:Variant.FakeAV.102
AvastWin32:MalwareX-gen [Trj]
TencentEmail-Worm.Win32.Lover.xha
EmsisoftGen:Variant.FakeAV.102 (B)
F-SecureHeuristic.HEUR/Malware
VIPREGen:Variant.FakeAV.102
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1892237d3221cfc5
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminWorm/Lover.a
VaristW32/Lover.B.gen!Eldorado
AviraHEUR/Malware
MAXmalware (ai score=82)
Antiy-AVLWorm[Email]/Win32.Lover.b
MicrosoftWorm:Win32/Agent.W
ZoneAlarmEmail-Worm.Win32.Lover.a
GDataGen:Variant.FakeAV.102
GoogleDetected
AhnLab-V3Malware/Gen.Generic.R567904
Acronissuspicious
VBA32BScope.Trojan.MulDrop
ALYacGen:Variant.FakeAV.102
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Lover!8.A6BE (TFE:2:6cttNuhVX6P)
YandexTrojan.GenAsa!zcehVw4vfxY
IkarusEmail-Worm.Win32.Lover.a
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Lover.A!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove FakeAV.102?

FakeAV.102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment