Fake

Mal/FakeAV-UF removal

Malware Removal

The Mal/FakeAV-UF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/FakeAV-UF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to access Bitcoin/ALTCoin wallets
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/FakeAV-UF?


File Info:

name: 59EBAC85ADA12A9C40AE.mlw
path: /opt/CAPEv2/storage/binaries/736cee45365d01ac1513de4be824109e0e7a7798132402dbe230db183a9caa22
crc32: E3D8AFFF
md5: 59ebac85ada12a9c40aea4bfdfe8b510
sha1: 6e9f5b58ca98f8172bce8f2f0194bc7351ed7496
sha256: 736cee45365d01ac1513de4be824109e0e7a7798132402dbe230db183a9caa22
sha512: db51729a7c310c8e1ca7e0010c7b9eef97330ef77f352b0342ca6071d014757f452430417270dc2756e19c1d428987ac372fe18b311e96000cf67f2f7a42de82
ssdeep: 24576:lTmz5FapQWLP8NoySJ7nReNceQfmrAPMYeU:p4FaOaP8NopnRz5fmrkMYe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125052315D2D758FACE062AB401F83A9056032B7E5C028E593D1C596DBAEB520B3FB3DD
sha3_384: 92a759fd8087b06b1a4938b23caa1dc968afb63ac0f0976217c1f5eb15a66a15c4d8d8183982969e060cbed738352c3f
ep_bytes: 9054596681e900ff0f825800000068a3
timestamp: 2013-07-19 17:18:19

Version Info:

0: [No Data]

Mal/FakeAV-UF also known as:

LionicTrojan.Win32.Generic.lKKk
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.59ebac85ada12a9c
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeeFakeAlert-FSZ!59EBAC85ADA1
MalwarebytesTrojan.MalPack.FFS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005485311 )
AlibabaVirTool:Win32/Obfuscator.18c3f235
K7GWTrojan ( 005485311 )
Cybereasonmalicious.8ca98f
CyrenW32/Kryptik.GUA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BONO
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Kryptik.crguqq
AvastWin32:Downloader-UWY [Trj]
TencentWin32.Trojan.Generic.Lqil
EmsisoftTrojan.VIZ.Gen.1 (B)
F-SecureBackdoor.BDS/Hlux.83713648
DrWebTrojan.PWS.Siggen1.14696
VIPRETrojan.VIZ.Gen.1
TrendMicroBKDR_KELIHOS.SMF
McAfee-GW-EditionBehavesLike.Win32.Upatre.cc
Trapminemalicious.high.ml.score
SophosMal/FakeAV-UF
SentinelOneStatic AI – Malicious PE
GDataTrojan.VIZ.Gen.1
JiangminTrojan/Generic.bitlr
WebrootTrojan.Dropper.Gen
AviraBDS/Hlux.83713648
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Hlux
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.BLUL@55d2qg
ArcabitTrojan.VIZ.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Kelihos.F
GoogleDetected
AhnLab-V3Trojan/Win32.Badur.R91550
BitDefenderThetaGen:NN.ZexaF.36738.ZmX@ayJd0Qi
ALYacTrojan.VIZ.Gen.1
VBA32Trojan.FakeAV.01657
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_KELIHOS.SMF
RisingHackTool.Obfuscator!8.236 (TFE:1:N0JdCKOUUmJ)
YandexBackdoor.Hlux!40+vB4ieIxA
IkarusBackdoor.Win32.Hlux
FortinetW32/Kelihos.BQGD!tr
AVGWin32:Downloader-UWY [Trj]
DeepInstinctMALICIOUS

How to remove Mal/FakeAV-UF?

Mal/FakeAV-UF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment