Fake

FakeAV.109 (file analysis)

Malware Removal

The FakeAV.109 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAV.109 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

How to determine FakeAV.109?


File Info:

crc32: 8DB7EF36
md5: 3fc43d2101509dcfb263eda09dea1640
name: 3FC43D2101509DCFB263EDA09DEA1640.mlw
sha1: 20b99dae1654f1dcb9b224ba8f51291cd00b3b22
sha256: dfc88dcfb2e6142320915c7aafbc25bf4874f1bde7f57182c086db6268c9fe75
sha512: 5560f911b02d39ef8b0bee090c8bdf33b2da46774af1cf32996f976481c2714f7cd265cbd96ee0f552d9d6c85fbf451fbae58bf11b3e934ef231800162299380
ssdeep: 3072:/T7kGa4SNLl8NvnZDTp8FF1j64947x3C8d:rJa4SNkYId
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

FakeAV.109 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055dd191 )
DrWebTrojan.Winlock.8128
CynetMalicious (score: 100)
ALYacGen:Variant.FakeAV.109
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.54995
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Foreign.9e9a240a
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.101509
SymantecTrojan.Ransomlock.Q!g3
ESET-NOD32a variant of Win32/Kryptik.BATS
APEXMalicious
AvastWin32:Crypt-PFS [Trj]
ClamAVWin.Ransomware.Delf-9828911-0
KasperskyTrojan-Ransom.Win32.Foreign.cklf
BitDefenderGen:Variant.FakeAV.109
NANO-AntivirusTrojan.Win32.Winlock.cqlocp
SUPERAntiSpywareTrojan.Agent/Gen-Unruy
MicroWorld-eScanGen:Variant.FakeAV.109
TencentWin32.Trojan.Foreign.Lpbw
Ad-AwareGen:Variant.FakeAV.109
SophosMal/Generic-R
ComodoTrojWare.Win32.Ransom.Foreign.DAB@5rvfiq
F-SecureTrojan.TR/Urausy.EB.11
BitDefenderThetaAI:Packer.C5F0424C14
VIPRETrojan.Win32.Reveton.a (v)
McAfee-GW-EditionRansom-FBOM!3FC43D210150
FireEyeGeneric.mg.3fc43d2101509dcf
EmsisoftGen:Variant.FakeAV.109 (B)
WebrootW32.Rogue.Gen
AviraTR/Urausy.EB.11
MicrosoftRansom:Win32/Urausy.C
ArcabitTrojan.FakeAV.109
AegisLabTrojan.Win32.Foreign.4!c
ZoneAlarmTrojan-Ransom.Win32.Foreign.cklf
GDataGen:Variant.FakeAV.109
AhnLab-V3Win-Trojan/Foreign.128512
McAfeeRansom-FBOM!3FC43D210150
MAXmalware (ai score=100)
VBA32OScope.Malware-Cryptor.Hlux
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
RisingRansom.Urausy!8.2B7 (CLOUD)
YandexTrojan.Foreign!zM5u+QTT9fo
IkarusVirus.Agent
FortinetW32/Foreign.CKLF!tr
AVGWin32:Crypt-PFS [Trj]
Qihoo-360Win32/Trojan.Foreign.HyoDEpsA

How to remove FakeAV.109?

FakeAV.109 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment