Fake

MSIL/FakeTool.AKX removal

Malware Removal

The MSIL/FakeTool.AKX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/FakeTool.AKX virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC

How to determine MSIL/FakeTool.AKX?


File Info:

name: 1A5B601A86A81E1889D6.mlw
path: /opt/CAPEv2/storage/binaries/502cf6ca83bd11ee14364264ccba04adcc514339bff64500ef13df9dbc57d953
crc32: C21FDF89
md5: 1a5b601a86a81e1889d69e4b6f2b630f
sha1: 9ddac32299ee92ac154f4ce7c82c1fc4e6a808e2
sha256: 502cf6ca83bd11ee14364264ccba04adcc514339bff64500ef13df9dbc57d953
sha512: 5e60b55130cb35e05041a6be04b075e8d86ecef805ebcb7d00b4a5745aae9fc83028633b6f8fe6dfd5c7d37975aec872a8f70f811c8b8b27226d92ea277045f9
ssdeep: 196608:Xt+3OOFuvBKN6NvphoWqF/pyECAL4xvPNhe:COOFWBg6Nvpqw9vq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1827633B6630626BBC1840B31CC07D2B97B516E052D39615F52DCBE9FBBBA0C67937260
sha3_384: d290a45862162c794f8c328c28b84f7d0018e92d85b19c345cae8c58c1c9d44a6203bde34de1ba8bb4b8a6610a3ac4be
ep_bytes: 558bec83c4f0b888534200e824f2fdff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: Quicky Translator
FileDescription: Quicky Translator 1.00 Installation
FileVersion: 1.00
LegalCopyright: Quicky Translator
Translation: 0x0409 0x04e4

MSIL/FakeTool.AKX also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SangforTrojan.Win32.FakeTool.8
CrowdStrikewin/malicious_confidence_60% (W)
K7GWHacktool ( 004ef0931 )
K7AntiVirusHacktool ( 004ef0931 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/FakeTool.AKX
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Diztakun.bpdh
NANO-AntivirusTrojan.Win32.Drop.eaorgj
AvastFileRepMalware [Trj]
SophosMal/Generic-R
DrWebTrojan.MulDrop6.25736
SentinelOneStatic AI – Suspicious PE
ZoneAlarmTrojan.Win32.Diztakun.bpdh
Ikarusnot-a-virus:Client-IRC.Win32
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
AVGFileRepMalware [Trj]
Cybereasonmalicious.299ee9

How to remove MSIL/FakeTool.AKX?

MSIL/FakeTool.AKX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment