Fake Trojan

Trojan:Win32/Fakecorr information

Malware Removal

The Trojan:Win32/Fakecorr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fakecorr virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)

How to determine Trojan:Win32/Fakecorr?


File Info:

name: 2DC80FD1478C19A8D7BE.mlw
path: /opt/CAPEv2/storage/binaries/0240d758044d786cd8036352cc23f407cd64c0bb4be44ab26432812f284a2a96
crc32: D18A34BF
md5: 2dc80fd1478c19a8d7be31233948f7f7
sha1: 009b69b5a324de00de872b9e3433b26b75d8783d
sha256: 0240d758044d786cd8036352cc23f407cd64c0bb4be44ab26432812f284a2a96
sha512: f24537f2fb0c55c55302c5aa79abf4b8993568f00464150fb99a9eaeb0e4cc36444c29402c0e2e15d2ee9ebabf5a20b89d0071847f04c1962fd4b9dcab1423db
ssdeep: 3072:8rDNlGM/wlmcj2fOYObL4DROvRNRz30D84Ax:OrGn2fF04DROvRfL3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119D36B0275E780B2C8AE487A146C4B566F7FA6148AF18B431F561ACFEF222D1DF35306
sha3_384: 930eef28515b4d3a9e16b156bcac26b53b07415e493da6ad5fb0a2bf01e467a04fef7ada83508fb1ac6413105d9b832e
ep_bytes: 6a606890724000e8b2050000bf940000
timestamp: 2009-03-16 14:39:24

Version Info:

0: [No Data]

Trojan:Win32/Fakecorr also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Fixer.j!c
MicroWorld-eScanTrojan.FakeAlert.AZO
FireEyeGeneric.mg.2dc80fd1478c19a8
SkyhighRansom-F.a
ALYacTrojan.FakeAlert.AZO
MalwarebytesMalware.AI.4205834918
ZillyaTrojan.Pincav.Win32.507
SangforSuspicious.Win32.Save.ins
AlibabaRansom:Win32/Fixer.47b8c9ce
Cybereasonmalicious.1478c1
ArcabitTrojan.FakeAlert.AZO
VirITTrojan.Win32.Generic.FZX
SymantecTrojan.Xrupter
Elasticmalicious (high confidence)
ESET-NOD32Win32/Adware.FileFixProfessional2009.A
CynetMalicious (score: 99)
McAfeeGenericRXAA-AA!2DC80FD1478C
ClamAVWin.Trojan.Agent-194424
KasperskyTrojan-Ransom.Win32.Fixer.a
BitDefenderTrojan.FakeAlert.AZO
NANO-AntivirusTrojan.Win32.Fixer.cqolke
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10be4ab6
TACHYONTrojan-Clicker/W32.Fakealert.139264
SophosTroj/Fakecor-A
F-SecureTrojan.TR/Ransom.Fixer.A.1
DrWebTrojan.Siggen3.42611
VIPRETrojan.FakeAlert.AZO
TrendMicroTROJ_XRUPTER.D
EmsisoftTrojan.FakeAlert.AZO (B)
IkarusPUA.FileFixProfessional2009
JiangminTrojan/Fixer.c
VaristW32/Renos!Generic
AviraTR/Ransom.Fixer.A.1
Antiy-AVLTrojan[Ransom]/Win32.Fixer
KingsoftWin32.Troj.Undef.a
XcitiumMalware@#1h2r5owcvfld4
MicrosoftTrojan:Win32/Fakecorr
ViRobotSpyware.Ransom.139264.A
ZoneAlarmTrojan-Ransom.Win32.Fixer.a
GDataTrojan.FakeAlert.AZO
GoogleDetected
BitDefenderThetaAI:Packer.6CBE0D971F
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Fixer
Cylanceunsafe
PandaTrj/Fixer
TrendMicro-HouseCallTROJ_XRUPTER.D
RisingTrojan.Fakecorr!8.B7C2 (TFE:5:XFJJtQHC8oP)
YandexTrojan.GenAsa!KYzpFItdcVk
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1135762.susgen
FortinetW32/Fakecor.A!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudRansomware:Win/FileFixProfessional2009.A

How to remove Trojan:Win32/Fakecorr?

Trojan:Win32/Fakecorr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment