Fake PUA

Win32:FakeDownload-G [PUP] removal guide

Malware Removal

The Win32:FakeDownload-G [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeDownload-G [PUP] virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:FakeDownload-G [PUP]?


File Info:

name: 012DA79E95F101A28593.mlw
path: /opt/CAPEv2/storage/binaries/f099aa42c67b0e667f42bca0442b59b09bc15c70fa0410ab780e574994add396
crc32: 821BC352
md5: 012da79e95f101a285931036c7fdfa60
sha1: 7e0b2e9670213f50c7514ac8377eaecea499d592
sha256: f099aa42c67b0e667f42bca0442b59b09bc15c70fa0410ab780e574994add396
sha512: fa3704fad130961de8eeedd61c19e1992aa62ccb8ec90eef308067ccbe1b93c4a1aea5d7e0d35565df0c64a74a9bded1cf18b4516b57bbc6c2054ecab77bd5d1
ssdeep: 12288:xJXLqdVsNjEV1rrFQVn+0qO0aC5SLh/6G+4ZB/1eOxX8aOek9sw4MB9FTA:xJXLKOqVJ++0+5SLh/6naB/13c4CFTA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CCE4BE91A50BF1BFCB430271919969F3B1385AB03D308CB79BD1EEB41EB0EA14955A37
sha3_384: 1ad61b9aa554ece43b45d1de31c553a66ca59f7d8c63437e6986bb130fd0a68c3a2ed8f414b79c351c5b83590452ecb5
ep_bytes: e88b360000e9000000006a146800df4f
timestamp: 2012-07-07 22:23:24

Version Info:

0: [No Data]

Win32:FakeDownload-G [PUP] also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.MultiPlug.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.61213571
McAfeeArtemis!012DA79E95F1
ZillyaAdware.MultiPlugGen.Win32.40
K7AntiVirusUnwanted-Program ( 004c73ee1 )
K7GWUnwanted-Program ( 004c73ee1 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Generic.D3A60B83
SymantecSMG.Heur!gen
APEXMalicious
BitDefenderTrojan.GenericKD.61213571
NANO-AntivirusRiskware.Win32.MultiPlug.dqbhkq
AvastWin32:FakeDownload-G [PUP]
Ad-AwareTrojan.GenericKD.61213571
EmsisoftTrojan.GenericKD.61213571 (B)
ComodoApplication.Win32.AdWare.MultiPlug.VA@5j28kp
BaiduWin32.Adware.Generic.bb
VIPRETrojan.GenericKD.61213571
TrendMicroTROJ_GEN.R03FC0OHA22
McAfee-GW-EditionBehavesLike.Win32.VirRansom.bc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.012da79e95f101a2
SophosMultiPlug (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare/MultiPlug.abty
GoogleDetected
Antiy-AVLTrojan/Generic.ASMalwS.3303
GDataTrojan.GenericKD.61213571
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.61213571
MAXmalware (ai score=81)
TrendMicro-HouseCallTROJ_GEN.R03FC0OHA22
RisingTrojan.Generic@AI.100 (RDML:nPxe7B0x1VeFSZ/OeAcobQ)
IkarusPUA.Generic
FortinetRiskware/Generic.AC.342374
AVGWin32:FakeDownload-G [PUP]
PandaTrj/CI.A

How to remove Win32:FakeDownload-G [PUP]?

Win32:FakeDownload-G [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment