Fake

About “Rogue:Win32/FakeRean” infection

Malware Removal

The Rogue:Win32/FakeRean is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue:Win32/FakeRean virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to stop active services
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Attempts to modify user notification settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
antiv2012.com

How to determine Rogue:Win32/FakeRean?


File Info:

crc32: BBF6E8BD
md5: ae9aca8ff7a5ee4d1aa6a7b14c84ecd5
name: AE9ACA8FF7A5EE4D1AA6A7B14C84ECD5.mlw
sha1: 5d80f1516cc61a92b6c5d10176395e0276d62f7e
sha256: dcb00e20d79df650236d40342dfe53b2a2b254faa349d31c668593af289ddb32
sha512: 4ec3b555300d023b33303f77221f86e55638ad0bde67842f2ee6129a0ff7cf4e6d85f97a99034e58d48ae50fd17546a5d9580ec1dc91c3a3b9186aa9ea7c1e6e
ssdeep: 12288:mc4DrrbqhR56pEV+ACnN56wIQzlyQuKu56wIQzlyQuKj:mZO2YPCN5f/zlfu5f/zlfj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Rogue:Win32/FakeRean also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.3111
FireEyeGeneric.mg.ae9aca8ff7a5ee4d
ALYacGen:Variant.Fugrafa.3111
CylanceUnsafe
VIPRERogue.Win32.Fakerean.n (v)
AegisLabTrojan.Win32.Generic.lGmj
SangforMalware
K7AntiVirusTrojan ( 003ff5411 )
BitDefenderGen:Variant.Fugrafa.3111
K7GWTrojan ( 003ff5411 )
Cybereasonmalicious.ff7a5e
CyrenW32/Zbot.SL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.FakeAV-13735
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Fakealert.bdjorz
ViRobotTrojan.Win32.A.CProtection.461056
RisingTrojan.Injector!8.C4 (TFE:3:hXgIruc62sG)
Ad-AwareGen:Variant.Fugrafa.3111
SophosML/PE-A + Mal/EncPk-AHS
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.Fakealert.20509
ZillyaTrojan.FakeAV.Win32.238768
TrendMicroTSPY_CPROTECTION_BL13291D.TOMC
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
EmsisoftGen:Variant.Fugrafa.3111 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/CProtection.be
AviraTR/Crypt.XPACK.Gen7
eGambitUnsafe.AI_Score_54%
MAXmalware (ai score=80)
Antiy-AVLTrojan[FakeAV]/Win32.CProtection
MicrosoftRogue:Win32/FakeRean
ArcabitTrojan.Fugrafa.DC27
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Fugrafa.3111
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CProtection.R44871
McAfeeArtemis!AE9ACA8FF7A5
VBA32TrojanFakeAV.CProtection
MalwarebytesMalware.AI.4277796299
PandaTrj/Genetic.gen
ZonerTrojan.Win32.27815
ESET-NOD32a variant of Win32/Injector.YRS
TrendMicro-HouseCallTSPY_CPROTECTION_BL13291D.TOMC
TencentMalware.Win32.Gencirc.10bc1461
YandexTrojan.GenAsa!IxZtTFfHw6c
IkarusVirus.Win32.CeeInject
FortinetW32/FakeAV.IY!tr
BitDefenderThetaGen:NN.ZexaF.34804.MmZ@a4CJsIpk
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM19.1.6CB1.Malware.Gen

How to remove Rogue:Win32/FakeRean?

Rogue:Win32/FakeRean removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment