Fake

NSIS:FakeAV-AR [Trj] removal tips

Malware Removal

The NSIS:FakeAV-AR [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:FakeAV-AR [Trj] virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine NSIS:FakeAV-AR [Trj]?


File Info:

name: 81A5B0782C000EC96CDE.mlw
path: /opt/CAPEv2/storage/binaries/ae8c20d24e7e9454b5e4c8d1921e27e8ec4b47ae6d62c83938722f0392b3ea71
crc32: C7784FDF
md5: 81a5b0782c000ec96cdefc35256873e8
sha1: 5a28e716512815086217b2b14bb1482fb1c8a16f
sha256: ae8c20d24e7e9454b5e4c8d1921e27e8ec4b47ae6d62c83938722f0392b3ea71
sha512: 8375c8e1a8257071f9475732324d13b9449f7770fdea028fee90108cc3777ff7fc44b8d95fa20aa6a222c4d7ba5cb6402ed65b9887710788e637d8c8330534b2
ssdeep: 1536:5pgpHzb9dZVX9fHMvG0D3XJpK2iZKRX77DiTM:zgXdZt9P6D3XJjiMdKI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164539D26F8C19473E4504C3512BBA7FAE3739DFB866E6D5783653F362A72046860B143
sha3_384: 0076a133e21972ac1251c41cb8b3160910f872b05cbf690453e4c386289fa4c8e6fcd39363ba9a8e444f3878a4623a25
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

NSIS:FakeAV-AR [Trj] also known as:

ZillyaTrojan.GenericKD.Win32.245013
SangforTrojan.Win32.Agent.Vgbi
AlibabaAdWare:Win32/FakeAV.3116bef8
Cybereasonmalicious.82c000
AvastNSIS:FakeAV-AR [Trj]
McAfee-GW-EditionBehavesLike.Win32.BadFile.kh
Trapminesuspicious.low.ml.score
XcitiumMalware@#20046jmibtas0
MicrosoftTrojan:Win32/Zpevdo.A
McAfeeArtemis!81A5B0782C00
Cylanceunsafe
AVGNSIS:FakeAV-AR [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (W)

How to remove NSIS:FakeAV-AR [Trj]?

NSIS:FakeAV-AR [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment