Fake

Win32:FakeMail-N [Trj] removal

Malware Removal

The Win32:FakeMail-N [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeMail-N [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Win32:FakeMail-N [Trj]?


File Info:

name: B8DCDD68220C0337C12A.mlw
path: /opt/CAPEv2/storage/binaries/10c4deb4389d8e71ea47c2e550d6f8b34cd4695e02289973460f4a9b35f37acb
crc32: CE3FB194
md5: b8dcdd68220c0337c12a60dfcdc041da
sha1: e7f725734125f3f4befcd133a2b198f86f120a0e
sha256: 10c4deb4389d8e71ea47c2e550d6f8b34cd4695e02289973460f4a9b35f37acb
sha512: 097f2b34d5d32423409e8d2f80fb26721b03904230966d19c2c1301ec344e62b33e2687dd8b7d685ff2c1b472bf5880726913d5608fbb45d3124e416f34a0f75
ssdeep: 192:41wxuvRJrUI0rH/+KiHbtgQmQ0M8wgD8nM5k8o0c1Px5+O4XXQkdIU13NTBuar0:Axhk2KiHbABwaAMe8oz9xgOCb513J0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1059261A5D5E300F9D27A46F54CEBB1F6B4623093FA228C4D1EC1B632158369768FE60D
sha3_384: 2fbd6d089ec5a9782b9a057ea1ff0b8e7074a792b534d8c1b80261d8237708ed09f1430ef1b57c610d25bcb10111b967
ep_bytes: b800804000608da80080ffff68e0bc19
timestamp: 2014-05-19 11:25:38

Version Info:

0: [No Data]

Win32:FakeMail-N [Trj] also known as:

BkavW32.FamVT.GeND.Trojan
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.b8dcdd68220c0337
ALYacTrojan.Ppatre.Gen.1
CylanceUnsafe
ZillyaTrojan.Generic.Win32.650363
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00564b2b1 )
BitDefenderTrojan.Ppatre.Gen.1
K7GWTrojan ( 00564b2b1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Ppatre.Gen.1
CyrenW32/S-29857617!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.Petite.N
APEXMalicious
ClamAVWin.Malware.Upatre-6912233-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Zbot.cykpux
RisingTrojan.Generic@AI.100 (RDMK:c6cYoz9o4Th7LfjrM86qLA)
Ad-AwareTrojan.Ppatre.Gen.1
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.E@5ag7i4
DrWebTrojan.DownLoad3.33216
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mm
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/DwnLdr-LOQ
IkarusTrojan.Win32.Krypt
JiangminTrojan.Generic.dbtxn
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASBOL.C6E4
MicrosoftTrojan:Win32/BlackMon!MSR
GDataTrojan.Ppatre.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.C3458307
McAfeeGenericRXAA-AA!B8DCDD68220C
MAXmalware (ai score=85)
VBA32TrojanSpy.Zbot
MalwarebytesTrojan.Email.FakeDoc
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentMalware.Win32.Gencirc.116475f1
YandexTrojan.GenAsa!+V7EyyfQ22g
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.E!tr
BitDefenderThetaGen:NN.ZexaF.34786.bmX@ayv41mi
AVGWin32:FakeMail-N [Trj]
Cybereasonmalicious.8220c0
AvastWin32:FakeMail-N [Trj]

How to remove Win32:FakeMail-N [Trj]?

Win32:FakeMail-N [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment