Fake Trojan

Trojan.Fakealert.41802 removal

Malware Removal

The Trojan.Fakealert.41802 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Fakealert.41802 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Mexican)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Fakealert.41802?


File Info:

name: EF7262A0C6BEF983D439.mlw
path: /opt/CAPEv2/storage/binaries/93669e93e602d4a1544bc0a4ccdce4bd1952b881aca7bde3e062400611451b71
crc32: AFE070B7
md5: ef7262a0c6bef983d439b64040b1aa88
sha1: 56780f6105bff84399b1a122dbcadafbb8ab8b38
sha256: 93669e93e602d4a1544bc0a4ccdce4bd1952b881aca7bde3e062400611451b71
sha512: ed1b25c33cac5c07449d24165ba7a27877ce1af48f93f78800665a514c0c53bc9df83887fa1f799a22d088dde24044f09a4dd7ed93f6c34194f9233c30813763
ssdeep: 24576:leY8MXMc6oMV/H5nkTb5LDOMtphWbmavhAd4svr6H0CgpHs:wYFA4OMtcma5U8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188A519C4607C34DBE08B29BB030BCA277B2715FA3AC250842BD4DD52456E5D7A7E4EAD
sha3_384: 2f1beb18207f64126c88b874a594ea055172f81a29127b16502a235a23381f36608d7c6d583fa0f8eb03fc7a1630193f
ep_bytes: 558bec6aff68502950006830e04f0064
timestamp: 2010-05-17 15:54:45

Version Info:

Comments:
CompanyName: Satinfo SL.
FileDescription: Utilidad Anti-Virus
FileVersion: 21, 10, 1, 25
InternalName: Elis
LegalCopyright: Copyright (C) 2010
LegalTrademarks:
OriginalFilename: Elis.EXE
PrivateBuild:
ProductName: Aplicación Elis
ProductVersion: 2, 10, 1, 25
SpecialBuild:
Translation: 0x0c0a 0x04b0

Trojan.Fakealert.41802 also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Fakealert.41802
FireEyeGeneric.mg.ef7262a0c6bef983
ALYacTrojan.Fakealert.41802
MalwarebytesAdware.ISTBar
ZillyaDownloader.IstBar.Win32.1158
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.0c6bef
CyrenW32/FakeAlert.CC.gen!Eldorado
SymantecML.Attribute.HighConfidence
BaiduWin32.Adware.SmartInstaller.a
TrendMicro-HouseCallTROJ_GEN.R002H0CKS21
ClamAVWin.Trojan.Istbar-213
Kasperskynot-a-virus:HEUR:WebToolbar.Win32.Estapa.heur
BitDefenderTrojan.Fakealert.41802
NANO-AntivirusTrojan.Win32.IstBar.igmsa
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Anpi
Ad-AwareTrojan.Fakealert.41802
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.TrojanDownloader.IstBar.~L@f815z
VIPREVirtumonde.a (fs)
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.Fakealert.41802 (B)
APEXMalicious
GDataTrojan.Fakealert.41802
JiangminTrojanDownloader.IstBar.pk
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!EF7262A0C6BE
MAXmalware (ai score=99)
VBA32BScope.Trojan.DiskWriter
CylanceUnsafe
RisingDownloader.Tibs!1.6620 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen

How to remove Trojan.Fakealert.41802?

Trojan.Fakealert.41802 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment