Fake

Should I remove “Win32/FakeDoc.A”?

Malware Removal

The Win32/FakeDoc.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/FakeDoc.A virus can do?

  • Injection (inter-process)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
wxanalytics.ru
a.tomx.xyz

How to determine Win32/FakeDoc.A?


File Info:

crc32: E3F5F898
md5: c116f27104480a496ea5f139135b407f
name: noticeoftender.pdf
sha1: 7f0235c75db1428bccf48f6a3f15acf8c4db9b97
sha256: c8a28d0bdfaa1be9a4a55a40218a73d542c8a0e926555c0cb17d8900d182dacb
sha512: b04cb3dabd12424accee4929a926fd3f8796df19f5a4300e7f97548c573c5276a73466a9810910663be5ecec9296a04ffa4611c2f9e3308714ddbbcb4c857d92
ssdeep: 98304:K8UsYYEOtUpgD3EAmgCRoE0kC9eQKyZURQ1EjT:K8UsvEOtUW3EAmbtIURQA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/FakeDoc.A also known as:

MicroWorld-eScanGen:Heur.Mint.Zard.36
FireEyeGeneric.mg.c116f27104480a49
CAT-QuickHealWorm.Fadok.A5
ALYacGen:Heur.Mint.Zard.36
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004c3bbe1 )
BitDefenderGen:Heur.Mint.Zard.36
K7GWTrojan ( 004c3bbe1 )
Cybereasonmalicious.104480
TrendMicroHT_FADOK_GA31119C.UVPM
BitDefenderThetaGen:NN.ZexaF.34084.ixW@aGLRtupk
CyrenW32/FakeDoc.F.gen!Eldorado
BaiduWin32.Worm.FakeDoc.a
TrendMicro-HouseCallHT_FADOK_GA31119C.UVPM
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-6723913-0
GDataGen:Heur.Mint.Zard.36
KasperskyTrojan.Win32.Agent.ifdx
AlibabaWorm:Win32/FakeDoc.f17f48b7
NANO-AntivirusTrojan.Win32.Rendoc.faojir
AvastWin32:WormX-gen [Wrm]
TencentMalware.Win32.Gencirc.10b6abd3
Ad-AwareGen:Heur.Mint.Zard.36
SophosTroj/FakeDoc-B
ComodoTrojWare.Win32.Scar.FAKD@5xdxi2
F-SecureTrojan.TR/ATRAPS.Gen4
DrWebWin32.HLLW.Rendoc.3
ZillyaTrojan.Scar.Win32.88546
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftWorm.FakeDoc (A)
APEXMalicious
F-ProtW32/FakeDoc.F.gen!Eldorado
JiangminWorm.Agent.ju
MaxSecureTrojan.Agent.ifdx
AviraTR/ATRAPS.Gen4
Antiy-AVLTrojan/Win32.Scar.jfya
Endgamemalicious (high confidence)
ArcabitTrojan.Mint.Zard.36
ZoneAlarmTrojan.Win32.Agent.ifdx
MicrosoftWorm:Win32/Fadok!rfn
AhnLab-V3Worm/Win32.Fadok.R189010
Acronissuspicious
McAfeeGenericRXAH-AG!C116F2710448
MAXmalware (ai score=100)
VBA32Trojan.Agent
MalwarebytesTrojan.FakeDoc
ZonerTrojan.Win32.61633
ESET-NOD32Win32/FakeDoc.A
RisingWorm.Fadok!1.A753 (CLOUD)
YandexTrojan.DownLoader!
IkarusWorm.Win32.Fakedoc
eGambitUnsafe.AI_Score_93%
FortinetW32/FakeDoc.A!worm
AVGWin32:WormX-gen [Wrm]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Virus.HideDoc.K

How to remove Win32/FakeDoc.A?

Win32/FakeDoc.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment