Fake Spy Trojan

What is “Trojan-FakeAV.Win32.SpyNoMore.f”?

Malware Removal

The Trojan-FakeAV.Win32.SpyNoMore.f is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-FakeAV.Win32.SpyNoMore.f virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan-FakeAV.Win32.SpyNoMore.f?


File Info:

name: AA06B1D1F1EE931F86F4.mlw
path: /opt/CAPEv2/storage/binaries/8f16db1df3f881fa3d6710306a2fbce76d82bb1418739a75a7a586d6ea4f3ae3
crc32: C4D295E7
md5: aa06b1d1f1ee931f86f415cf840410e8
sha1: a51ff776919498ae20e78a1486ba3498a28985e4
sha256: 8f16db1df3f881fa3d6710306a2fbce76d82bb1418739a75a7a586d6ea4f3ae3
sha512: 9b98ac3de31ccbc87b709e174a4e7c035e0639fdd58e9497eb29ecd62a1737086c37b2fb62999a960419efa05ec7f6199f330bb46db019a7a62ffecdd4f1d2ce
ssdeep: 49152:fI49cqw3sEPk1+Feh+AyGHnq1CFdPJ+52+TRjbWJUTJvjXVg1x:wtPQkeh+ArHnq1CPR+zWJWJ8x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BD533C38FE00A2DE5AF0C3544F3B5342B36E00C15193956A718FE79E8854BAE6B569F
sha3_384: 5081cd65b61fb0e845b2f1fcb1ee87d0656c65bfeff4d4a1c8b9cec29474724c7472f82da673c167b73539b311244770
ep_bytes: 81ec7c01000053555633f65789742418
timestamp: 2006-01-24 18:42:56

Version Info:

0: [No Data]

Trojan-FakeAV.Win32.SpyNoMore.f also known as:

LionicTrojan.Win32.SpyNoMore.c!c
SkyhighGeneric PWS.afb
McAfeeGeneric PWS.afb
Cylanceunsafe
SangforTrojan.Win32.SpyNoMore.f
AlibabaTrojan:Win32/SpyNoMore.9f0c1d81
VirITFraudTool.SNM.A
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Adware.SpyNoMore
TrendMicro-HouseCallADW_SPYNOMORE
ClamAVWin.Trojan.FakeAV-305
KasperskyTrojan-FakeAV.Win32.SpyNoMore.f
NANO-AntivirusTrojan.Win32.FakeAV.fffato
F-SecureAdware.ADSPY/AdSpy.Gen
DrWebTrojan.Fakealert.15520
TrendMicroADW_SPYNOMORE
SophosGeneric Reputation PUA (PUA)
JiangminTrojan/SpyNoMore.b
GoogleDetected
AviraADSPY/AdSpy.Gen
VaristW32/ABAdware.BPDV-2815
Antiy-AVLTrojan[FakeAV]/Win32.SpyNoMore
Kingsoftmalware.kb.a.867
MicrosoftPUA:Win32/Creprote
XcitiumMalware@#176isf7ibv2sy
ViRobotAdware.SpyNoMore.R.2999296
ZoneAlarmTrojan-FakeAV.Win32.SpyNoMore.f
VBA32Riskware.SpyNoMore
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Suspicious
RisingTrojan.ScrInject!8.A (TOPIS:E1:NoVmI6BSoCK)
Ikarusnot-a-virus:FraudTool.Win32.SpyNoMore
FortinetRiskware/SpyNoMore
DeepInstinctMALICIOUS

How to remove Trojan-FakeAV.Win32.SpyNoMore.f?

Trojan-FakeAV.Win32.SpyNoMore.f removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment