Categories: FakeVirus

Virus:Win32/Fakefire.A removal instruction

The Virus:Win32/Fakefire.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Fakefire.A virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Fakefire.A?


File Info:

name: AE0B7FAD61206D45F2A4.mlwpath: /opt/CAPEv2/storage/binaries/2c04c26eb80b51771373f10027385a9c2326f72664834ba526740ba64cd03706crc32: A9104DACmd5: ae0b7fad61206d45f2a4a34d285db936sha1: e8226f8da51a614c333c7866a4d6f883fcb95a09sha256: 2c04c26eb80b51771373f10027385a9c2326f72664834ba526740ba64cd03706sha512: 023c6a4f458592c8366c91710765aee185ab8e1b1a652591211b0bb87794f29d03a3573aa590c51d720f1b4b8105010e540a3dab0155b297d7d02a508f740e7cssdeep: 12288:BPBIeeIeQBlMXWPHCH9Eq+0BbSox1QuQRlHw:BPBIFItLMmPHCHPb99QRlwtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T19F252901F7E7E17AEDB316B1583981201676BD354B3886CF2385762D1EB13C2A672B27sha3_384: 236a87ec48385f9058892b0249f637e9bcaf0716e48f249c19dcfedee5b06bd139289b2f1fa16541bda3af0fa5d83c0bep_bytes: 558becb82c150000e88a030000535657timestamp: 2001-07-19 22:01:47

Version Info:

0: [No Data]

Virus:Win32/Fakefire.A also known as:

Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Zbot.tpDK
MicroWorld-eScan Dropped:Win32.Worm.VB.NXJ
FireEye Generic.mg.ae0b7fad61206d45
CAT-QuickHeal Trojan.VB.S692133
McAfee Artemis!AE0B7FAD6120
Sangfor [MICROSOFT VISUAL BASIC 5.0]
Cybereason malicious.d61206
Baidu Win32.Trojan.VB.t
Cyren W32/S-d8e31bcf!Eldorado
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/VB.QZU
APEX Malicious
ClamAV Win.Dropper.Pajetbin-7136153-0
Kaspersky Trojan.Win32.Agent.qwiffa
BitDefender Dropped:Win32.Worm.VB.NXJ
NANO-Antivirus Trojan.Win32.VB.tole
Avast Win32:VB-FBX
Tencent Malware.Win32.Gencirc.10b80253
Emsisoft Dropped:Win32.Worm.VB.NXJ (B)
DrWeb Win32.HLLP.Woner
Zillya Trojan.Zbot.Win32.208012
TrendMicro TROJ_VB.BJR
McAfee-GW-Edition BehavesLike.Win32.Generic.dh
Sophos Mal/Generic-S
SentinelOne Static AI – Malicious PE
GData Win32.Trojan.Vb.IL
Avira TR/Agent.57344.1474
Arcabit Win32.Worm.VB.NXJ
Microsoft Virus:Win32/Fakefire.A
Cynet Malicious (score: 100)
AhnLab-V3 Spyware/Win32.RL_Zbot.R265544
Acronis suspicious
VBA32 TScope.Trojan.VB
ALYac Dropped:Win32.Worm.VB.NXJ
MAX malware (ai score=84)
Malwarebytes VB.Virus.FileInfector.DDS
TrendMicro-HouseCall TROJ_VB.BJR
Rising Trojan.KillAV!1.66BF (CLASSIC)
Yandex Trojan.GenAsa!IPLOeyvnoUg
Ikarus Virus.Win32.VB.gp
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Agent.F7E1!tr
BitDefenderTheta Gen:NN.ZexaF.34742.7mZ@aS2w!nb
AVG Win32:VB-FBX
CrowdStrike win/malicious_confidence_90% (D)

How to remove Virus:Win32/Fakefire.A?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Win32/Autoit.OPN information

The Win32/Autoit.OPN is considered dangerous by lots of security experts. When this infection is active,…

4 mins ago

Malware.AI.3788326785 removal

The Malware.AI.3788326785 is considered dangerous by lots of security experts. When this infection is active,…

20 mins ago

What is “Trojan.Generic.35619263”?

The Trojan.Generic.35619263 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Generic.Dacic.1A7FA519.A.F34D6DE8 removal instruction

The Generic.Dacic.1A7FA519.A.F34D6DE8 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “Babar.143901”?

The Babar.143901 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

UDS:NetTool.Win64.FRP removal tips

The UDS:NetTool.Win64.FRP is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago