Categories: FakePUA

Win32:FakeDownload-G [PUP] removal guide

The Win32:FakeDownload-G [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeDownload-G [PUP] virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:FakeDownload-G [PUP]?


File Info:

name: 012DA79E95F101A28593.mlwpath: /opt/CAPEv2/storage/binaries/f099aa42c67b0e667f42bca0442b59b09bc15c70fa0410ab780e574994add396crc32: 821BC352md5: 012da79e95f101a285931036c7fdfa60sha1: 7e0b2e9670213f50c7514ac8377eaecea499d592sha256: f099aa42c67b0e667f42bca0442b59b09bc15c70fa0410ab780e574994add396sha512: fa3704fad130961de8eeedd61c19e1992aa62ccb8ec90eef308067ccbe1b93c4a1aea5d7e0d35565df0c64a74a9bded1cf18b4516b57bbc6c2054ecab77bd5d1ssdeep: 12288:xJXLqdVsNjEV1rrFQVn+0qO0aC5SLh/6G+4ZB/1eOxX8aOek9sw4MB9FTA:xJXLKOqVJ++0+5SLh/6naB/13c4CFTAtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T1CCE4BE91A50BF1BFCB430271919969F3B1385AB03D308CB79BD1EEB41EB0EA14955A37sha3_384: 1ad61b9aa554ece43b45d1de31c553a66ca59f7d8c63437e6986bb130fd0a68c3a2ed8f414b79c351c5b83590452ecb5ep_bytes: e88b360000e9000000006a146800df4ftimestamp: 2012-07-07 22:23:24

Version Info:

0: [No Data]

Win32:FakeDownload-G [PUP] also known as:

Bkav W32.AIDetect.malware1
Lionic Riskware.Win32.MultiPlug.1!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.61213571
McAfee Artemis!012DA79E95F1
Zillya Adware.MultiPlugGen.Win32.40
K7AntiVirus Unwanted-Program ( 004c73ee1 )
K7GW Unwanted-Program ( 004c73ee1 )
CrowdStrike win/malicious_confidence_70% (W)
Arcabit Trojan.Generic.D3A60B83
Symantec SMG.Heur!gen
APEX Malicious
BitDefender Trojan.GenericKD.61213571
NANO-Antivirus Riskware.Win32.MultiPlug.dqbhkq
Avast Win32:FakeDownload-G [PUP]
Ad-Aware Trojan.GenericKD.61213571
Emsisoft Trojan.GenericKD.61213571 (B)
Comodo Application.Win32.AdWare.MultiPlug.VA@5j28kp
Baidu Win32.Adware.Generic.bb
VIPRE Trojan.GenericKD.61213571
TrendMicro TROJ_GEN.R03FC0OHA22
McAfee-GW-Edition BehavesLike.Win32.VirRansom.bc
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.012da79e95f101a2
Sophos MultiPlug (PUA)
SentinelOne Static AI – Malicious PE
Jiangmin AdWare/MultiPlug.abty
Google Detected
Antiy-AVL Trojan/Generic.ASMalwS.3303
GData Trojan.GenericKD.61213571
Cynet Malicious (score: 100)
ALYac Trojan.GenericKD.61213571
MAX malware (ai score=81)
TrendMicro-HouseCall TROJ_GEN.R03FC0OHA22
Rising Trojan.Generic@AI.100 (RDML:nPxe7B0x1VeFSZ/OeAcobQ)
Ikarus PUA.Generic
Fortinet Riskware/Generic.AC.342374
AVG Win32:FakeDownload-G [PUP]
Panda Trj/CI.A

How to remove Win32:FakeDownload-G [PUP]?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

How to remove “Malware.AI.2670838656”?

The Malware.AI.2670838656 is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Malware.AI.3626015347 removal

The Malware.AI.3626015347 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Trojan.Generic.35742373 removal instruction

The Trojan.Generic.35742373 is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

How to remove “Win32.Virtob.4.Gen”?

The Win32.Virtob.4.Gen is considered dangerous by lots of security experts. When this infection is active,…

32 mins ago

Application.Bundler.DomaIQ.Q (B) removal guide

The Application.Bundler.DomaIQ.Q (B) is considered dangerous by lots of security experts. When this infection is…

2 hours ago

Jatif.4890 information

The Jatif.4890 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago