Fake

Should I remove “FakeAv.24”?

Malware Removal

The FakeAv.24 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAv.24 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Creates a copy of itself
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine FakeAv.24?


File Info:

name: 7EDFD137784E8328A23A.mlw
path: /opt/CAPEv2/storage/binaries/d28d89b5e90e337f9e565e525d63e4fda1e28349f3f1f2c2a568c329f04670e1
crc32: DA4FEA65
md5: 7edfd137784e8328a23a005ff54ac9c8
sha1: 0988c979c21e5f8f67e578c2bb96d69968f62698
sha256: d28d89b5e90e337f9e565e525d63e4fda1e28349f3f1f2c2a568c329f04670e1
sha512: 9002c44f8809c1e70c7c49a0e2f887e640134224be8b6dcecd41c42e45fe1683a5b4d2086ba274f6bb21853ea1b5b69b0e9430d14ae0b5b8693793ec09b4e5cf
ssdeep: 3072:OLS6TTnczCqD17qNc+lK5kRq/kt5K0pBmXB7NPITO6peEfe9M1Cy:OOC0CqD1sxJqV0PofPITrece9S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0241213BC56C9B6D89ED3730B379271337D86A12ED8030BE121C451EAFAAECD944B59
sha3_384: 47567164f12ad09fd3743fa368e337d77bf4a05118b3ffdf339727fc0e18d763f70bb51ae72d93754008a48e0aa9297f
ep_bytes: 33c0b910200001030183ec786a008bcc
timestamp: 2011-01-12 13:59:58

Version Info:

0: [No Data]

FakeAv.24 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.FakeAv.24
ClamAVWin.Trojan.FakeAV-8295
CAT-QuickHealFraudTool.Security
McAfeeGeneric FakeAV.ama
VIPREGen:Variant.FakeAv.24
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0020f4661 )
K7GWTrojan ( 0020f4661 )
Cybereasonmalicious.7784e8
CyrenW32/SuspPack.DA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ASRB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.FakeAv.24
NANO-AntivirusTrojan.Win32.Fakealert.crbeqn
SUPERAntiSpywareTrojan.Agent/Gen-FraudShield
AvastWin32:FakeAV-BFI [Trj]
TencentMalware.Win32.Gencirc.10b6c177
EmsisoftGen:Variant.FakeAv.24 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Fakealert.20231
TrendMicroWORM_KELIHOS.SM
McAfee-GW-EditionGeneric FakeAV.ama
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7edfd137784e8328
SophosMal/EncPk-XM
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.FakeAv.24
JiangminTrojan/Generic.efvl
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.FakeAV.BK@2oiy03
ArcabitTrojan.FakeAv.24
ViRobotTrojan.Win32.A.FakeAV.56581
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRogue:Win32/Winwebsec
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R829
BitDefenderThetaGen:NN.ZexaF.36318.nqZ@aewf@Bji
ALYacGen:Variant.FakeAv.24
VBA32Trojan.FakeAV.01657
Cylanceunsafe
PandaTrj/Agent.FX
TrendMicro-HouseCallWORM_KELIHOS.SM
RisingTrojan.Win32.Kryptik.p (CLASSIC)
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Krypt.N!tr.dldr
AVGWin32:FakeAV-BFI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove FakeAv.24?

FakeAv.24 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment