Fake

About “FakeAv.119 (B)” infection

Malware Removal

The FakeAv.119 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAv.119 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Accessed credential storage registry keys
  • Yara detections observed in process dumps, payloads or dropped files

How to determine FakeAv.119 (B)?


File Info:

name: CC0D8A25FD91E7434A90.mlw
path: /opt/CAPEv2/storage/binaries/de823a8270ab7d64a80f3ddd3850286ce730cd388a1b270efc5e11444733ed20
crc32: DA8520D5
md5: cc0d8a25fd91e7434a9080101e886f6e
sha1: f39ca8c05bf98f769cafb6ee50a63d74c3e92c71
sha256: de823a8270ab7d64a80f3ddd3850286ce730cd388a1b270efc5e11444733ed20
sha512: e74a7e43e25b0dfb00abb126d6c630588850813dafbe20842b57f40f15eb002c5bfb035512c70c8fcc72ec501c4f4e9b74c7a3dc9f1796f63987bb027f9b51c1
ssdeep: 98304:TvvwjOia8yafvq8efvsvz/Y6zz0kXnFOs5:ziLaQfvq8efvsvzQYfFP5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123F533D9B6D9AFAEE155013B0013AF9FD8F7CF020FB692AF039C557689611CAE005693
sha3_384: f0ad7641efe2ea025fef3cee58fedf16e83ea6ab3dbe41ae34735b72face6d133499a5f0c00f7ce08c7bc1a01140a787
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-05-03 14:08:38

Version Info:

0: [No Data]

FakeAv.119 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Farfli.4!c
DrWebTrojan.SpyBot.324
MicroWorld-eScanGen:Variant.FakeAv.119
FireEyeGeneric.mg.cc0d8a25fd91e743
CAT-QuickHealTrojan.Aksula.A
SkyhighBehavesLike.Win32.Backdoor.wc
McAfeeArtemis!CC0D8A25FD91
Cylanceunsafe
ZillyaTrojan.Farfli.Win32.88734
SangforBackdoor.Win32.Farfli.V6zx
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaAdWare:Win32/BaiduSearch.75b29ade
K7GWTrojan ( 004cbeb01 )
K7AntiVirusTrojan ( 004cbeb01 )
ArcabitTrojan.FakeAv.119
BitDefenderThetaAI:Packer.A42B4C9720
VirITTrojan.Win32.Agent.AWGD
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Generickdz-6957625-0
KasperskyHEUR:Trojan.Win32.Farfli.gen
BitDefenderGen:Variant.FakeAv.119
NANO-AntivirusTrojan.Win32.Scar.bblurm
AvastWin32:Dropper-JQQ [Drp]
TencentWin32.Trojan.Agent.Jmnw
EmsisoftGen:Variant.FakeAv.119 (B)
F-SecureBackdoor.BDS/Zegost.birna
BaiduWin32.Trojan.Dialer.d
VIPREGen:Variant.FakeAv.119
TrendMicroBKDR_ZEGOST.SM34
Trapminesuspicious.low.ml.score
SophosMal/Packer
IkarusTrojan.Win32.Farfli
JiangminServer-FTP.Serv-U.bw
VaristW32/ABRisk.LRGY-3141
AviraTR/Dropper.Gen2
Antiy-AVLGrayWare[Server-FTP]/Win32.Serv-U
XcitiumMalware@#2fhh8ksxzmomf
MicrosoftBackdoor:Win32/Farfli.FT!MTB
ZoneAlarmHEUR:Trojan.Win32.Farfli.gen
GDataWin32.Application.DuoteSearch.A3
GoogleDetected
AhnLab-V3Trojan/Win32.PcClient.R121863
VBA32SScope.Trojan.VTFlooder
ALYacGen:Variant.FakeAv.119
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ZEGOST.SM34
RisingPUA.Presenoker!8.F608 (CLOUD)
YandexTrojan.GenAsa!pd90PKR7MRk
SentinelOneStatic AI – Suspicious PE
FortinetW32/GenKryptik.BJAB!tr
AVGWin32:Dropper-JQQ [Drp]
DeepInstinctMALICIOUS

How to remove FakeAv.119 (B)?

FakeAv.119 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment