Fake Trojan

GenPack:Trojan.FakeAV.LAK (file analysis)

Malware Removal

The GenPack:Trojan.FakeAV.LAK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Trojan.FakeAV.LAK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine GenPack:Trojan.FakeAV.LAK?


File Info:

name: DE962278C875E6DDCCB2.mlw
path: /opt/CAPEv2/storage/binaries/22bdf666925089251d865cc73b3f16c83789ed03c54a3fdefa8c141f71757b80
crc32: F8DC6A7C
md5: de962278c875e6ddccb2bc69a6659919
sha1: 5203e999534182619f83be6b11b407e44aaca8bc
sha256: 22bdf666925089251d865cc73b3f16c83789ed03c54a3fdefa8c141f71757b80
sha512: 2d80beb3a9f39ed8e2892a15f915c7778ab8513adbcd205d3c3a9069b5dc5be3ebf26950d3d1f724785706cabcef20fc03c9c8fb1dc3ef3a7962cc94f5f3dfc3
ssdeep: 6144:1bJjXTMUjGkeoK56Xb+FBxxlKmzIFk75qrMY:19sUjYoaWb+FBxXJIFk9qrz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E434021BBB2C104BE902C67181B44BA54BF0DC10987A5B97D5CC29FABCE81D29D7D8DD
sha3_384: e8c471003ad580bc4f03835d02798493ac6d7e3343da6daafa9d860872ec14492b6a0a71239909bd25e434e65a6d727e
ep_bytes: ba1901000023458889d141b956280000
timestamp: 2008-09-21 16:35:12

Version Info:

0: [No Data]

GenPack:Trojan.FakeAV.LAK also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.CodecPack.li7d
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.FakeAV.LAK
SkyhighBehavesLike.Win32.Dropper.dc
McAfeeFakeAV-KS.gen.y
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.FakeAV.Win32.6017
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
AlibabaTrojanDownloader:Win32/Katusha.7fb0f63c
K7GWTrojan-Downloader ( 0055e3da1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36802.ouX@amT33mm
VirITTrojan.Win32.FraudLoad.XDKJ
SymantecVirusDoctor
ESET-NOD32Win32/TrojanDownloader.FakeAlert.AEY
APEXMalicious
TrendMicro-HouseCallTROJ_FAKEAV.SMAS
ClamAVWin.Downloader.FraudLoad-67
KasperskyPacked.Win32.Katusha.o
BitDefenderGenPack:Trojan.FakeAV.LAK
NANO-AntivirusTrojan.Win32.Katusha.dqvtmk
AvastWin32:Trojan-gen
TencentWin32.Packed.Katusha.Etgl
EmsisoftGenPack:Trojan.FakeAV.LAK (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Fakealert.16467
VIPREGenPack:Trojan.FakeAV.LAK
TrendMicroTROJ_FAKEAV.SMAS
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.de962278c875e6dd
SophosMal/FakeAV-CZ
IkarusTrojan.Win32.FakeAV
JiangminTrojanDownloader.FraudLoad.nnl
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
VaristW32/FakeAlert.IT.gen!Eldorado
Antiy-AVLTrojan[Packed]/Win32.Katusha
KingsoftWin32.Troj.Undef.a
MicrosoftRogue:Win32/FakeVimes
XcitiumTrojWare.Win32.Downloader.Fraudload.VB@2vmiwt
ArcabitGenPack:Trojan.FakeAV.LAK
ViRobotTrojan.Win32.Downloader.235008.P
ZoneAlarmPacked.Win32.Katusha.o
GDataGenPack:Trojan.FakeAV.LAK
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.FakeAV.R325
VBA32SScope.Malware-Cryptor.TDSS
ALYacGenPack:Trojan.FakeAV.LAK
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
RisingAdware.FakeVimes!8.1365F (TFE:2:hmzvFluwkRJ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1326835.susgen
FortinetW32/FAKEAV.FS!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.8c875e
DeepInstinctMALICIOUS
alibabacloudVirtool:Win/FakeAlert.AEY

How to remove GenPack:Trojan.FakeAV.LAK?

GenPack:Trojan.FakeAV.LAK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment