Adware Fake Spy

Win32/Adware.FakeAntiSpy.AT (file analysis)

Malware Removal

The Win32/Adware.FakeAntiSpy.AT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.FakeAntiSpy.AT virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable browser security warnings

How to determine Win32/Adware.FakeAntiSpy.AT?


File Info:

crc32: 327D343A
md5: 1736d404a02a93edd8f748cd947d3491
name: 1736D404A02A93EDD8F748CD947D3491.mlw
sha1: 48e3761bf022448f4b56116ec8ce7c6b397fad45
sha256: b7a26777ad0a9984dc9809ca1e01b40eb76a6e602a422b9dab020465757d6306
sha512: e11821894cd82dab09041d43cb6dbecf4908b426ec27df43f037fb4eef6c65342bf06eb95a0fd9872bdcd11813af0ac239daed1cb30f9fb54bb4539a570a4951
ssdeep: 12288:AkgVPXIx/ZpLD6EW5nfFko08b2iq3c+1QdSOgokaq6+nUJX:HgKFZpLDrgfF301iq3pQUzPKJX
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Adware.FakeAntiSpy.AT also known as:

K7AntiVirusTrojan ( 7000000f1 )
DrWebTrojan.Siggen3.41494
CynetMalicious (score: 100)
ALYacGen:Variant.FakeAV.18
CylanceUnsafe
ZillyaTrojan.FakeAV.Win32.82317
AlibabaRansom:Win32/Blocker.2b2da945
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.4a02a9
CyrenW32/A-8c58d75e!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Adware.FakeAntiSpy.AT
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Fakeav-71468
KasperskyTrojan-Ransom.Win32.Blocker.fsoo
BitDefenderGen:Variant.FakeAV.18
NANO-AntivirusTrojan.Win32.TrjGen.dubrpl
MicroWorld-eScanGen:Variant.FakeAV.18
TencentWin32.Trojan.Fakeav.Dwti
Ad-AwareGen:Variant.FakeAV.18
SophosMal/FakeAV-FO
ComodoMalware@#xp6mm6ylpo4l
BitDefenderThetaGen:NN.ZelphiF.34692.QmGfaCY4tFjk
VIPREFraudTool.Win32.FakeVimes!delf (v)
McAfee-GW-EditionFakeAV-PJ.gen.n
FireEyeGeneric.mg.1736d404a02a93ed
EmsisoftGen:Variant.FakeAV.18 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Fakeav.ytb
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1114825
Antiy-AVLTrojan/Generic.ASMalwS.1864DF5
KingsoftWin32.Heur.KVM099.a.(kcloud)
MicrosoftRogue:Win32/FakePAV
GDataGen:Variant.FakeAV.18
AhnLab-V3Trojan/Win32.FakeAV.R6213
McAfeeFakeAV-PJ.gen.n
MAXmalware (ai score=100)
VBA32Trojan.FakeAV
PandaGeneric Malware
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.FakeAV!PUpEa2bm7hI
IkarusTrojan.Win32.FakeAV
FortinetW32/FakeAV.DLCP!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Adware.FakeAntiSpy.AT?

Win32/Adware.FakeAntiSpy.AT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment