Fake

Mal/FakeAV-UF removal

Malware Removal

The Mal/FakeAV-UF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/FakeAV-UF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to access Bitcoin/ALTCoin wallets
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/FakeAV-UF?


File Info:

name: 2D6C3D29FF8F47665FC9.mlw
path: /opt/CAPEv2/storage/binaries/17192a3368677631d08e7f4c4b9d19698591dcdc62239df8b257f3a7942e838d
crc32: D100550D
md5: 2d6c3d29ff8f47665fc9262bce34d840
sha1: 6e3ccff40c3b2013f7d06ae9b3c1a8e8798cbb6e
sha256: 17192a3368677631d08e7f4c4b9d19698591dcdc62239df8b257f3a7942e838d
sha512: f1c2a58be15bc5d77ea6a5ee30d927ef64f41d7cea8a472f47ad7d7684d43072aa319ca7598631725f4a25210239387521eb5fa20fa0d4eee0d5aa594946e734
ssdeep: 12288:5uo8Uf4GZv8wjkWzj0AEkmt5yR0i8hVMFimQCcTcgpUldUFwq35RBGYrCfKRX2g/:5uo8UQqvArkmt5yR0iWr+BCd5nGCsRg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F052307B7732104C5D7BF32EFB7F6061708C59271938D4A7AAB5AA5773B64C0BAA042
sha3_384: 587fc339f3e42304ff05b9a115ad66d6c1625ac5c73bb1ff67c18e35191e5a85f53e4d91e39bea057c5740f512cba672
ep_bytes: 54fc58661d00ff724f51baa7bfbfff58
timestamp: 2012-12-03 11:09:11

Version Info:

0: [No Data]

Mal/FakeAV-UF also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lKKk
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.2d6c3d29ff8f4766
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeeGeneric-FANP!2D6C3D29FF8F
MalwarebytesTrojan.MalPack.FFS
VIPRETrojan.VIZ.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f72a1 )
BitDefenderTrojan.VIZ.Gen.1
K7GWTrojan ( 0040f72a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Kryptik.ao
VirITTrojan.Win32.Siggen1.TSG
CyrenW32/Tepfer.T.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BONO
APEXMalicious
ClamAVWin.Packed.Hlux-9759694-0
KasperskyTrojan-PSW.Win32.Tepfer.sbav
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Tepfer.dwitbf
MicroWorld-eScanTrojan.VIZ.Gen.1
AvastWin32:Downloader-UWY [Trj]
TencentWin32.Trojan-QQPass.QQRob.Njgl
EmsisoftTrojan.VIZ.Gen.1 (B)
F-SecureTrojan.TR/Urausy.69136824
DrWebTrojan.PWS.Siggen1.13498
ZillyaTrojan.Kryptik.Win32.794051
TrendMicroBKDR_KELIHOS.SMF
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cc
Trapminemalicious.high.ml.score
SophosMal/FakeAV-UF
IkarusTrojan.ScreenLocker_s
GDataTrojan.VIZ.Gen.1
JiangminTrojan/PSW.Tepfer.cepm
WebrootW32.Malware.Gen
AviraTR/Urausy.69136824
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Tepfer.sbav
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.BLUK@54x5jt
ArcabitTrojan.VIZ.Gen.1
ZoneAlarmTrojan-PSW.Win32.Tepfer.sbav
MicrosoftBackdoor:Win32/Kelihos.F
GoogleDetected
AhnLab-V3Spyware/Win32.Zbot.R90150
VBA32Heur.Trojan.Hlux
ALYacTrojan.VIZ.Gen.1
TACHYONTrojan-PWS/W32.Tepfer.835600.E
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_KELIHOS.SMF
RisingSpyware.Zbot!8.16B (TFE:2:sCJ89UWXW0P)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.6714873.susgen
FortinetW32/Kryptik.BDPK!tr
BitDefenderThetaGen:NN.ZexaF.36738.ZmX@a85d38b
AVGWin32:Downloader-UWY [Trj]
Cybereasonmalicious.40c3b2
DeepInstinctMALICIOUS

How to remove Mal/FakeAV-UF?

Mal/FakeAV-UF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment