Fake

Win32:FakeAlert-CWC [Trj] malicious file

Malware Removal

The Win32:FakeAlert-CWC [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeAlert-CWC [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP

How to determine Win32:FakeAlert-CWC [Trj]?


File Info:

name: 1F455DC3501D0893B105.mlw
path: /opt/CAPEv2/storage/binaries/431b7edfd314e364b6358e1248a34ddb8334d98441e3e92f33b92fa34d1e95c3
crc32: 8713F1B9
md5: 1f455dc3501d0893b10568bd28ca770a
sha1: 0add48a4713ff64f862aec87080601373eaceb1a
sha256: 431b7edfd314e364b6358e1248a34ddb8334d98441e3e92f33b92fa34d1e95c3
sha512: 172ebce43c636834bf99b543824c589ede35f723904babede0b099da87594136bf6df9a9b8eaf099b31789f1244791f77d5a6f2c0e1b1e9227d0baff9778e2be
ssdeep: 24576:jlplkkkDAQF0oTPah5RpyUBJ+1DHVPscYA:/mzk5h5RIb2cYA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F0523223F150825E55975B2DD07CABECA2EEE0A6615AF8079DC373A3F72567DC12308
sha3_384: 533ed0325f49ba15f2c1e4448c7b0ffc2b821d9c1808c21aa40820551469fa8f2c723a4c0297e73f0956095d676dd166
ep_bytes: ff15243040002bd281f200425700fece
timestamp: 2011-03-21 18:21:34

Version Info:

0: [No Data]

Win32:FakeAlert-CWC [Trj] also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
CynetMalicious (score: 100)
CAT-QuickHealFraudTool.Security
McAfeePWS-Zbot.gen.ain
MalwarebytesTrojan.LameShield
ZillyaTrojan.Tepfer.Win32.37228
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005042e61 )
K7GWTrojan ( 005042e61 )
Cybereasonmalicious.3501d0
VirITTrojan.Win32.Generic.ENR
CyrenW32/FakeAlert.UN.gen!Eldorado
SymantecSecShieldFraud!gen7
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AJFJ
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Bredolab.aaxp
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Tepfer.whxai
MicroWorld-eScanTrojan.VIZ.Gen.1
AvastWin32:FakeAlert-CWC [Trj]
Ad-AwareTrojan.VIZ.Gen.1
EmsisoftTrojan.VIZ.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.AISL@4psha1
DrWebBackDoor.Slym.604
VIPRETrojan.VIZ.Gen.1
TrendMicroTROJ_KRYPTK.SMJY
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1f455dc3501d0893
SophosML/PE-A + Mal/FakeAV-OY
SentinelOneStatic AI – Malicious PE
GDataTrojan.VIZ.Gen.1
JiangminBackdoor/Bredolab.nmi
AviraTR/FakeAlert.uro
Antiy-AVLTrojan/Generic.ASMalwS.1F1
ArcabitTrojan.VIZ.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicrosoftBackdoor:Win32/Kelihos.F
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R31372
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=87)
VBA32Heur.Trojan.Hlux
CylanceUnsafe
TrendMicro-HouseCallTROJ_KRYPTK.SMJY
RisingTrojan.FakeAV!1.9972 (CLASSIC)
YandexTrojan.GenAsa!Kn15gXcoBNQ
IkarusTrojan-PSW.Win32.Tepfer
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AGAI!tr
BitDefenderThetaGen:NN.ZexaF.34592.YqW@amuBK5ci
AVGWin32:FakeAlert-CWC [Trj]
PandaAdware/SystemTool
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32:FakeAlert-CWC [Trj]?

Win32:FakeAlert-CWC [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment