Virus

Virus:Win32/Fipeg!A information

Malware Removal

The Virus:Win32/Fipeg!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Fipeg!A virus can do?

  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates an autorun.inf file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Virus:Win32/Fipeg!A?


File Info:

crc32: D2CBE41D
md5: 660861fc04fb75cc5fa955e211b36711
name: 660861FC04FB75CC5FA955E211B36711.mlw
sha1: 6a470cae1fa8d502b0eda2f37c0c9a9c215f8485
sha256: b1b923241fe861fb3b8b7733f845557dc18f69a71640c5e827c2c97659d11488
sha512: 6ddd81d463f0d324596648a8672f41a40a6586e38a27839582dcb2deba9c22cd54d67cffa245ef3d39be871c0a53c5f4113907bc4cff9a3e3c536292ebad1562
ssdeep: 3072:3biet78Ua2e2NGhqjLzK1di2Sbiet78U:LiettPnNGhqL9iett
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Virus:Win32/Fipeg!A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.74346
FireEyeGeneric.mg.660861fc04fb75cc
ALYacGen:Variant.Midie.74346
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e4041 )
BitDefenderGen:Variant.Midie.74346
K7GWTrojan ( 0055e4041 )
Cybereasonmalicious.c04fb7
BaiduWin32.Virus.Xorer.l
CyrenW32/Risk.FJRN-7411
SymantecW32.Pagipef
APEXMalicious
AvastWin32:Dh-A [Heur]
ClamAVWin.Trojan.Agent-357629
KasperskyTrojan-PSW.Win32.Ruftar.bfuu
AlibabaMalware:Win32/Dorpal.ali1000029
NANO-AntivirusTrojan.Win32.Cossta.ctljs
ViRobotTrojan.Win32.A.Swisyn.32768.L
RisingWorm.Agent.xg (CLOUD)
Ad-AwareGen:Variant.Midie.74346
EmsisoftGen:Variant.Midie.74346 (B)
ComodoWorm.Win32.AutoRun.~CMU@19ms8q
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Bweah
TrendMicroWORM_AGENT.HCM
McAfee-GW-EditionBehavesLike.Win32.Autorun.cm
SophosML/PE-A + W32/Fipeg-A
IkarusWorm.Win32.Small
JiangminWorm/Viking.rs
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Cossta
KingsoftWin32.PSWTroj.Ruftar.bf.(kcloud)
MicrosoftVirus:Win32/Fipeg.gen!A
GridinsoftTrojan.Win32.Agent.vb!s1
ArcabitTrojan.Midie.D1226A
ZoneAlarmTrojan-PSW.Win32.Ruftar.bfuu
GDataWin32.Worm.Pagepif.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.R61019
Acronissuspicious
McAfeeW32/Autorun.worm.bfz
VBA32TrojanPSW.Ruftar
MalwarebytesNimnul.Virus.FileInfector.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Small.NAV
TrendMicro-HouseCallWORM_AGENT.HCM
TencentWorm.Win32.AutoRun.qua
YandexTrojan.GenAsa!Z1sSWV79N4U
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Xorer
FortinetW32/Xorer.DR!tr
BitDefenderThetaGen:NN.ZexaF.34590.hqZ@aul0aegb
AVGWin32:Dh-A [Heur]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Virus.Win32.Diskgen.AE

How to remove Virus:Win32/Fipeg!A?

Virus:Win32/Fipeg!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment