Fake Trojan

Trojan.FakeAlert.AUF (file analysis)

Malware Removal

The Trojan.FakeAlert.AUF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeAlert.AUF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.FakeAlert.AUF?


File Info:

name: 8D6DB4D2E685EF52F442.mlw
path: /opt/CAPEv2/storage/binaries/42dcd967c618a248ba84d5d7ee939e4cbacb60d94f71d9916f4b8380edd2ec70
crc32: 1976EE13
md5: 8d6db4d2e685ef52f44273c7c1b4d6d5
sha1: cf361cf93c5651882bd13e8c9c790afb7c08d018
sha256: 42dcd967c618a248ba84d5d7ee939e4cbacb60d94f71d9916f4b8380edd2ec70
sha512: c39550bee035adc0a5446e295edef72a32be4e3228ac2cdfccfd594561eec4265bb9c8339b53d726e8ba161b7c4a59b53df7cb7a114fcd07cfb98c6982d2f66a
ssdeep: 768:kvvU0fxUjeep++TYE6gXdXYH7Ext9sgLJB0zdFK:Ivfp9MYgV4gtudU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADD2C0B6F1C217F7F5D8F9B47663F23BC2665315B1B0C82207B2959825A201FF90B865
sha3_384: 583d1205f5a1b2702da179065d851176bda7ffccb9a746ab760e16f12b8648ec6599450c0bf27bd66ed22f12f5540ef2
ep_bytes: 33d0e98cfeffff8bc983c40468351f36
timestamp: 2009-01-07 00:35:10

Version Info:

0: [No Data]

Trojan.FakeAlert.AUF also known as:

BkavW32.CNCtdss.Heur
LionicHacktool.Win32.TDSS.kYL1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.FakeAlert.AUF
FireEyeGeneric.mg.8d6db4d2e685ef52
SkyhighBehavesLike.Win32.Downloader.mc
ALYacTrojan.FakeAlert.AUF
VIPRETrojan.FakeAlert.AUF
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f10006011 )
BitDefenderTrojan.FakeAlert.AUF
K7GWTrojan ( f10006011 )
Cybereasonmalicious.93c565
ArcabitTrojan.FakeAlert.AUF
BitDefenderThetaAI:Packer.4FF3026220
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EH
APEXMalicious
KasperskyPacked.Win32.TDSS.a
AlibabaTrojan:Win32/Bulta.360552d3
NANO-AntivirusTrojan.Win32.TDSS.bjiof
ViRobotTrojan.Win32.Tdss.30208.BH
AvastWin32:Jifas [Trj]
RisingTrojan.Kryptik!1.998C (CLASSIC)
EmsisoftTrojan.FakeAlert.AUF (B)
F-SecureRogue:W32/SpyGuard.gen!A
DrWebTrojan.Packed.365
TrendMicroWORM_TDSS.SMR
Trapminesuspicious.low.ml.score
SophosMal/TDSS-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminPack.TDSS.Gen
WebrootW32.Alureon.Rootkit
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Alureon.gen
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.HeurC.KVMH008.a
XcitiumWin32.PkdTdss@1r1qyw
MicrosoftTrojan:Win32/Alureon.CO
ZoneAlarmPacked.Win32.TDSS.a
GDataTrojan.FakeAlert.AUF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.R33887
VBA32Trojan.TDSS.01414
TACHYONTrojan/W32.TDSS.30208.G
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_TDSS.SMR
IkarusTrojan-Downloader.Win32.Renos.AQ
MaxSecureTrojan.Malware.15050.susgen
FortinetW32/Tdss.E!tr
AVGWin32:Jifas [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.FakeAlert.AUF?

Trojan.FakeAlert.AUF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment