Fake

FakeAv.119 removal instruction

Malware Removal

The FakeAv.119 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FakeAv.119 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

www.wk1888.com
www.af0575.com
www.fz0575.com

How to determine FakeAv.119?


File Info:

crc32: 5D2F91B8
md5: d793018cb7742d997be146c60b98aa80
name: server.exe
sha1: 1f5a6da5be20ae589758577e4877a5e666ddd5b9
sha256: d0a9946d47771db70901b46558a1c653849609f9f6fbc38404cad9e4dd029333
sha512: 05bb7661d0a8677d9c4d05325b8367261473ce861cbb2caf3271ccbd1c5ef95c51042fce9a9b9971bbddcf978edfe7f766d5dd3604a603390a47180a76b68071
ssdeep: 3072:rfP9ZGFwgvRLLCzOYFDq+UdnIPPlMzcsofIw+KaX0LcHLkMIIRf:L96wgvRHCzOYtqlGyzcsX3KA0LQIQRf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

FakeAv.119 also known as:

BkavW32.MokaviN.Trojan
MicroWorld-eScanGen:Variant.FakeAv.119
FireEyeGeneric.mg.d793018cb7742d99
CAT-QuickHealTrojan.Aksula.A
Qihoo-360Win32/Trojan.Dropper.567
McAfeeGenericRXHX-QM!D793018CB774
CylanceUnsafe
VIPREBackdoor.Win32.Zegost.ad (v)
SangforMalware
K7AntiVirusTrojan ( 004c53ca1 )
BitDefenderGen:Variant.FakeAv.119
K7GWTrojan ( 004c53ca1 )
Cybereasonmalicious.cb7742
Invinceaheuristic
BitDefenderThetaAI:Packer.9DF4DB3620
SymantecBackdoor.Zegost!gen2
APEXMalicious
AvastWin32:Dropper-JQQ [Drp]
ClamAVWin.Malware.Generickdz-6957625-0
GDataGen:Variant.FakeAv.119
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Bonke.fjhhvm
TencentTrojan.Win32.Zegost.a
Ad-AwareGen:Variant.FakeAv.119
F-SecureBackdoor.BDS/Zegost.birna
BaiduWin32.Trojan.Dialer.a
ZillyaTrojan.Dialer.Win32.14236
TrendMicroBKDR_ZEGOST.SM34
EmsisoftGen:Variant.FakeAv.119 (B)
IkarusVirus.Win32.Vundo
JiangminTrojan/Generic.ajyoe
WebrootW32.Trojan.Gen
AviraBDS/Zegost.birna
MAXmalware (ai score=88)
Endgamemalicious (high confidence)
ArcabitTrojan.FakeAv.119
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.AD
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C366239
Acronissuspicious
VBA32BScope.Backdoor.Zegost
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.ABTK
TrendMicro-HouseCallBKDR_ZEGOST.SM34
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazoz1nBRz6fWEaBeQv07XEFj)
YandexTrojan.Kryptik!wnNTA3B9Pro
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Farfli.OC!tr
AVGWin32:Dropper-JQQ [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove FakeAv.119?

FakeAv.119 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment