Fake

FakeAV.2 removal guide

Malware Removal

The FakeAV.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAV.2 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine FakeAV.2?


File Info:

name: 06282997D20E9C75A4E6.mlw
path: /opt/CAPEv2/storage/binaries/09077488746ba1c82978c33db552ebecf4658538343269a4003eb821373a49f4
crc32: 21EAB3DB
md5: 06282997d20e9c75a4e69e13201be52b
sha1: d544096c305bacadeaed5a45bb21a4f7eeeda643
sha256: 09077488746ba1c82978c33db552ebecf4658538343269a4003eb821373a49f4
sha512: 32929afa611bf1316a2b484523723016980aaaf6593b25016968a025f08e58fdee11517cdd87bab54521e67c15a360ad990d6c860ee402da7f1560e6baf67233
ssdeep: 24576:6qvoP4PpqJrLBJGIEN+MRMH43mnOlGTWI+lXI5LRqQAA2l:6qgPuqJnBJGIEYq3bGTWlXI58Qy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D45F24A8A93A1B1E95246775192737F49357B1321CCA9BFA3A3FC47C8321D1AA343CD
sha3_384: 3ae7dd31b136b18be3657bfc2b09f5b077398e1c2c9dc4665be2f172851f74353d35d5b8b3eb2614fa591b4be77e68f0
ep_bytes: 558bec6aff68f8c94c00909090909090
timestamp: 2020-04-29 14:03:19

Version Info:

0: [No Data]

FakeAV.2 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.FakeAV.2
FireEyeGeneric.mg.06282997d20e9c75
ALYacGen:Variant.FakeAV.2
CylanceUnsafe
K7AntiVirusTrojan ( 0056f46b1 )
BitDefenderGen:Variant.FakeAV.2
K7GWTrojan ( 0056f46b1 )
Cybereasonmalicious.7d20e9
BitDefenderThetaAI:Packer.8D98488220
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
RisingTrojan.Generic@AI.99 (RDMK:cmRtazoU270QWOfqliKcPWIuJu66)
Ad-AwareGen:Variant.FakeAV.2
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.FakeAV.2 (B)
IkarusTrojan-Proxy.Win32.Small
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.FakeAV.2
GDataGen:Variant.FakeAV.2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C107502
Acronissuspicious
McAfeeGenericRXCN-OZ!06282997D20E
VBA32BScope.Trojan.Witch
MalwarebytesMachineLearning/Anomalous.95%
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove FakeAV.2?

FakeAV.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment