Fake

Win32:FakeAlert-CHF [Trj] removal tips

Malware Removal

The Win32:FakeAlert-CHF [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeAlert-CHF [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify user notification settings

How to determine Win32:FakeAlert-CHF [Trj]?


File Info:

name: C32ABCA8FB67A0FDEAE8.mlw
path: /opt/CAPEv2/storage/binaries/2754ace43bb75ac618c9aa25690e9eecd84e375ac164d420a3ed35029eef3320
crc32: AE8CE576
md5: c32abca8fb67a0fdeae84090d4101232
sha1: 47d19558665991e182ae18f097f91f5f377fcf8a
sha256: 2754ace43bb75ac618c9aa25690e9eecd84e375ac164d420a3ed35029eef3320
sha512: c363d381ba97bdf6ed44f91fee6e6cefbfbebd5d3c6492f7a209573e6e3f93f06561d740bf18034b12b6524a89651850e09166b2455591fe5bbd6a7077901e36
ssdeep: 6144:pI/WWPrGRbApWJcYK5cpiHTaf032UH369nkVt3IDg7D9THWv2azgNGqpX:pIQ3dacmTafQxqp61IDgP9THiWp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3A4025265874228E85FB8F029E4958D666EFC2A43A5070B63F43D177E723E3EF1211E
sha3_384: 7a32c0415bcb91fe79d70bf19987f58e09085fd97aa44c41c667044e3fdaae8f0fc49808da0d37b6efac57fb2fef01cc
ep_bytes: 6a606878fc4200e8e30e0000bf940000
timestamp: 2012-04-01 18:57:52

Version Info:

0: [No Data]

Win32:FakeAlert-CHF [Trj] also known as:

LionicTrojan.Win32.Agent.lxbh
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.ZOF.2
CAT-QuickHealFraudTool.Security
VIPREGen:Heur.ZOF.2
SangforARMADILLO17
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaPacked:Win32/Katusha.739b168d
K7GWTrojan ( 00390f6f1 )
K7AntiVirusTrojan ( 00390f6f1 )
CyrenW32/FakeAlert.TN.gen!Eldorado
SymantecTrojan.FakeAV!gen91
APEXMalicious
AvastWin32:FakeAlert-CHF [Trj]
CynetMalicious (score: 100)
KasperskyPacked.Win32.Katusha.x
BitDefenderGen:Heur.ZOF.2
NANO-AntivirusTrojan.Win32.TrjGen.covkjd
SUPERAntiSpywareTrojan.Agent/Gen-MalPE
TencentWin32.Trojan.Generic.Svha
Ad-AwareGen:Heur.ZOF.2
DrWebTrojan.Siggen.65111
ZillyaTrojan.Kryptik.Win32.358610
TrendMicroMal_Cerber-20c
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Mal/FakeAV-KL
Paloaltogeneric.ml
WebrootW32.Rogue.Gen
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.24D
ArcabitTrojan.ZOF.2
ViRobotTrojan.Win32.A.Downloader.454656.AF
ZoneAlarmPacked.Win32.Katusha.x
AhnLab-V3Trojan/Win32.FakeAV.R22992
VBA32BScope.Trojan.Occamy
MAXmalware (ai score=83)
RisingTrojan.Generic@AI.100 (RDMK:JatXlnCl9qSsc2/arSMpwA)
YandexTrojan.GenAsa!565CV6Uamqg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.SmartFortress.B
FortinetW32/Kryptik.GQEQ!tr
AVGWin32:FakeAlert-CHF [Trj]
PandaTrj/Resdec.c

How to remove Win32:FakeAlert-CHF [Trj]?

Win32:FakeAlert-CHF [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment