Fake Virus

Virus:Win32/Fakefire.A removal instruction

Malware Removal

The Virus:Win32/Fakefire.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Fakefire.A virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Fakefire.A?


File Info:

name: AE0B7FAD61206D45F2A4.mlw
path: /opt/CAPEv2/storage/binaries/2c04c26eb80b51771373f10027385a9c2326f72664834ba526740ba64cd03706
crc32: A9104DAC
md5: ae0b7fad61206d45f2a4a34d285db936
sha1: e8226f8da51a614c333c7866a4d6f883fcb95a09
sha256: 2c04c26eb80b51771373f10027385a9c2326f72664834ba526740ba64cd03706
sha512: 023c6a4f458592c8366c91710765aee185ab8e1b1a652591211b0bb87794f29d03a3573aa590c51d720f1b4b8105010e540a3dab0155b297d7d02a508f740e7c
ssdeep: 12288:BPBIeeIeQBlMXWPHCH9Eq+0BbSox1QuQRlHw:BPBIFItLMmPHCHPb99QRlw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F252901F7E7E17AEDB316B1583981201676BD354B3886CF2385762D1EB13C2A672B27
sha3_384: 236a87ec48385f9058892b0249f637e9bcaf0716e48f249c19dcfedee5b06bd139289b2f1fa16541bda3af0fa5d83c0b
ep_bytes: 558becb82c150000e88a030000535657
timestamp: 2001-07-19 22:01:47

Version Info:

0: [No Data]

Virus:Win32/Fakefire.A also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.tpDK
MicroWorld-eScanDropped:Win32.Worm.VB.NXJ
FireEyeGeneric.mg.ae0b7fad61206d45
CAT-QuickHealTrojan.VB.S692133
McAfeeArtemis!AE0B7FAD6120
Sangfor[MICROSOFT VISUAL BASIC 5.0]
Cybereasonmalicious.d61206
BaiduWin32.Trojan.VB.t
CyrenW32/S-d8e31bcf!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VB.QZU
APEXMalicious
ClamAVWin.Dropper.Pajetbin-7136153-0
KasperskyTrojan.Win32.Agent.qwiffa
BitDefenderDropped:Win32.Worm.VB.NXJ
NANO-AntivirusTrojan.Win32.VB.tole
AvastWin32:VB-FBX
TencentMalware.Win32.Gencirc.10b80253
EmsisoftDropped:Win32.Worm.VB.NXJ (B)
DrWebWin32.HLLP.Woner
ZillyaTrojan.Zbot.Win32.208012
TrendMicroTROJ_VB.BJR
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Vb.IL
AviraTR/Agent.57344.1474
ArcabitWin32.Worm.VB.NXJ
MicrosoftVirus:Win32/Fakefire.A
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.RL_Zbot.R265544
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacDropped:Win32.Worm.VB.NXJ
MAXmalware (ai score=84)
MalwarebytesVB.Virus.FileInfector.DDS
TrendMicro-HouseCallTROJ_VB.BJR
RisingTrojan.KillAV!1.66BF (CLASSIC)
YandexTrojan.GenAsa!IPLOeyvnoUg
IkarusVirus.Win32.VB.gp
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.F7E1!tr
BitDefenderThetaGen:NN.ZexaF.34742.7mZ@aS2w!nb
AVGWin32:VB-FBX
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Virus:Win32/Fakefire.A?

Virus:Win32/Fakefire.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment