Fake

Should I remove “Rogue.FakeAV”?

Malware Removal

The Rogue.FakeAV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue.FakeAV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Rogue.FakeAV?


File Info:

name: AB27C3CC0AB76AD06F5C.mlw
path: /opt/CAPEv2/storage/binaries/f54c35cd56c468038ff46857f77d97eb90642d110cfda5ae3bd86ce4a2a9cc0f
crc32: 02D96CA6
md5: ab27c3cc0ab76ad06f5c02b088014cc8
sha1: 9ae2870402299cd70bdecff18cdfb73ea019effc
sha256: f54c35cd56c468038ff46857f77d97eb90642d110cfda5ae3bd86ce4a2a9cc0f
sha512: 1dfbe9bc6e3a2c8583aebe6e36326967b316089585d264f067e18b4ac8e6849241303994198e9a25c2f17164c9dfefa2d838bc19b5c6da4447536d0e2a5ac41e
ssdeep: 24576:R2G/nvxW3WaqIWe9DrE6MPY4I6kdVw3h/w5sgCp2Q6Vjvy2iACgLRvg:RbA3h9VY6MPRk6w5sxp2Q6VjvfTLRI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165758D127B500851EAF26BF225E6216036D759F0093E755B6FC0A139E0FE0ADEE5CDA3
sha3_384: ff7db9d98da633a7bfd61bf3c861573e14cbe815efb21b464a20b3e4a934992ec5901f507cc4f6af59a16896a0d4e649
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 17:50:20

Version Info:

0: [No Data]

Rogue.FakeAV also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Makop.trQA
FireEyeGeneric.mg.ab27c3cc0ab76ad0
McAfeeArtemis!AB27C3CC0AB7
CylanceUnsafe
VIPREApplication.Deceptor.AYW
SangforTrojan.Win32.Agent.vho
K7AntiVirusTrojan ( 00577fa21 )
BitDefenderApplication.Deceptor.AYW
K7GWTrojan ( 00577fa21 )
Cybereasonmalicious.c0ab76
ArcabitApplication.Deceptor.AYW
CyrenW32/Trojan.WRYZ-0485
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32MSIL/Hoax.FakeAV.U
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-FakeAV.MSIL.Agent.gen
AlibabaHoax:MSIL/FakeAV.b2a7e48b
MicroWorld-eScanApplication.Deceptor.AYW
RisingTrojan.FakeAV!1.D2B0 (CLASSIC)
Ad-AwareApplication.Deceptor.AYW
SophosGeneric PUA JK (PUA)
ComodoMalware@#1mulubdtx7nh4
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftApplication.Deceptor.AYW (B)
WebrootW32.Trojan.Gen
MAXmalware (ai score=76)
Antiy-AVLTrojan/Generic.ASMalwS.6C57
KingsoftWin32.Troj.Diztakun.bs.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!rfn
ViRobotTrojan.Win32.Z.Agent.1557506
GDataApplication.Deceptor.AYW
AhnLab-V3Malware/Win32.Generic.C4339723
ALYacApplication.Deceptor.AYW
MalwarebytesRogue.FakeAV
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CD622
TencentWin32.Trojan.Diztakun.Lmkl
YandexHoax.FakeAV!1FZy1+cs6MI
SentinelOneStatic AI – Suspicious SFX
MaxSecureTrojan.Malware.114489585.susgen
FortinetRiskware/FakeAV
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Rogue.FakeAV?

Rogue.FakeAV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment