Fake

How to remove “Win32:FakeAlert-DCG [Trj]”?

Malware Removal

The Win32:FakeAlert-DCG [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeAlert-DCG [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics

How to determine Win32:FakeAlert-DCG [Trj]?


File Info:

name: 874F22D94B3F1E7A3246.mlw
path: /opt/CAPEv2/storage/binaries/c39a96b49a1977500cdf4e1a6a91084239555d7fa5e247f3f54276dc47581c46
crc32: 736E4475
md5: 874f22d94b3f1e7a32468f6a2fef3b31
sha1: 96b12310314d64b3c2adae6c3f3ecd03f57c26a8
sha256: c39a96b49a1977500cdf4e1a6a91084239555d7fa5e247f3f54276dc47581c46
sha512: a594df170fe4f4f3cf1172eeab0391601bd1da8e5204727bc368355c996a552d032a68b4bffcbd0acc455afbc4b7a16a8de174fd8864315e03fbb17d064585aa
ssdeep: 12288:ong+Kckth97vOWRJ9zwIhvgBXy1K1S3BbrvqwfpAR1BiS7sxZOyX2PjGDmKYC:Xncch90IhvgBXz1Q9vqwBYF74G3Kr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172F433964821C080E7167C7066AF2333CB6BFD855C67DE9BDD71F2509AB024DA8FD924
sha3_384: 72be665f5b8f31a31819b963b8d1ca1794f91b814b267dc4573b207274852f7934d480b4b4769fbd8bec3083846cee5a
ep_bytes: 68004040005f8d35ec2f40006a1d59f3
timestamp: 2012-08-31 23:11:12

Version Info:

0: [No Data]

Win32:FakeAlert-DCG [Trj] also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lmka
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Lethic.B
ALYacTrojan.VIZ.Gen.1
MalwarebytesGeneric.Rogue.Fake.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.94b3f1
BaiduWin32.Trojan.Kryptik.ur
CyrenW32/FakeAlert.WP.gen!Eldorado
SymantecSecShieldFraud!gen10
ESET-NOD32a variant of Win32/Kryptik.ARUZ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.FakeAV.bfyosg
MicroWorld-eScanTrojan.VIZ.Gen.1
AvastWin32:FakeAlert-DCG [Trj]
RisingTrojan.Kryptik!1.A81D (CLASSIC)
Ad-AwareTrojan.VIZ.Gen.1
EmsisoftTrojan.VIZ.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.ARLI@4t2kfq
F-SecureTrojan.TR/Winwebsec.ioinw
DrWebBackDoor.Slym.1375
VIPRETrojan.VIZ.Gen.1
TrendMicroWORM_KELIHOS.SMB
McAfee-GW-EditionBehavesLike.Win32.VirRansom.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.874f22d94b3f1e7a
SophosML/PE-A + Mal/Zbot-KR
IkarusTrojan-PSW.Win32.Tepfer
GDataTrojan.VIZ.Gen.1
JiangminTrojan/Tepfer.Gen
AviraTR/Winwebsec.ioinw
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Heur.KVMH004.a.(kcloud)
ArcabitTrojan.VIZ.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Kelihos.F
GoogleDetected
AhnLab-V3Trojan/Win32.Tepfer.R48460
Acronissuspicious
McAfeeBackDoor-FJW
VBA32BScope.Trojan.FakeAV.8113
TrendMicro-HouseCallWORM_KELIHOS.SMB
TencentWin32.Trojan.Generic.Xylw
YandexTrojan.GenAsa!nU3DF3gNMw8
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.X!tr
BitDefenderThetaGen:NN.ZexaF.34726.UqW@aeGK9Sh
AVGWin32:FakeAlert-DCG [Trj]
PandaTrj/Tepfer.B
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:FakeAlert-DCG [Trj]?

Win32:FakeAlert-DCG [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment