Fake

W32/FakeFire-L removal tips

Malware Removal

The W32/FakeFire-L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/FakeFire-L virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine W32/FakeFire-L?


File Info:

name: D616B35AB43A43AD683F.mlw
path: /opt/CAPEv2/storage/binaries/00360c9ffba47e728df84f30cd33b41d06649a43ed774d92ca147f1ef220b3de
crc32: 711369AA
md5: d616b35ab43a43ad683f63c17f57b432
sha1: 04944a489e48c5dd29c14f2dcc7f0319c7e5d1c7
sha256: 00360c9ffba47e728df84f30cd33b41d06649a43ed774d92ca147f1ef220b3de
sha512: b351360ee241345a950489ead5c4df7525fa73e0257074b6301844477ffd55da999f0ba5cb649a93962b00c756392fcfa4d9883fc49ea4f6c2fa34ca1a20714c
ssdeep: 24576:14nlj94nljTbL8iHFLHgZpJEzXVav9MkN6/i+FMhrRoNk7BZpwaewsAjbA5:xLnHFLHkJEEv9Ma6/ivhrRokpDljb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15BE55B037650D633D4AE057539E182675DE5BDA10B22899B3388BFAE9933FC257F0326
sha3_384: 6f96b177373725996e5e4195efe46c67cf6822195656fb0df29097ac81431af1cfea251f321e460673f69ea23d242c16
ep_bytes: 68e0244000e8eeffffff000000000000
timestamp: 2007-08-17 12:43:04

Version Info:

0: [No Data]

W32/FakeFire-L also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.AutoRun.trSR
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.97176
FireEyeGeneric.mg.d616b35ab43a43ad
CAT-QuickHealW32.AutoRun.A5
SkyhighBehavesLike.Win32.Generic.vm
McAfeeGenericRXVJ-MH!D616B35AB43A
Cylanceunsafe
VIPRETrojan.GenericKDZ.97176
SangforWorm.Win32.VB.DiskBinder
K7AntiVirusTrojan ( 00558d391 )
Alibabavirus:Win32/InfectPE.ali2000007
K7GWTrojan ( 00558d391 )
Cybereasonmalicious.89e48c
ArcabitTrojan.Generic.D17B98
BitDefenderThetaAI:Packer.41644ADB1F
VirITWin32.Vindor.A
SymantecW32.Pajetbin
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.NAR
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Vindor-9886047-0
KasperskyWorm.Win32.AutoRun.vx
BitDefenderTrojan.GenericKDZ.97176
NANO-AntivirusTrojan.Win32.AutoRun.bqzoew
AvastWin32:WormX-gen [Wrm]
TencentWorm.Win32.Autorun.pc
EmsisoftTrojan.GenericKDZ.97176 (B)
BaiduWin32.Trojan.VB.t
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.547
ZillyaWorm.AutoRun.Win32.21124
TrendMicroWORM_AUTORUN.BTM
SophosW32/FakeFire-L
IkarusTrojan.Autorun
JiangminWorm.AutoRun.bnt
VaristW32/Pajetbin.A.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.AutoRun.vx
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.VB.~HL@5500p
MicrosoftTrojan:Win32/Vindor.B
ZoneAlarmWorm.Win32.AutoRun.vx
GDataWin32.Worm.Pajetbin.A
GoogleDetected
AhnLab-V3Worm/Win.AutoRun.R459478
Acronissuspicious
VBA32Worm.AutoRun
ALYacTrojan.GenericKDZ.97176
TACHYONBanker/W32.Banbra.Gen
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallWORM_AUTORUN.BTM
RisingWorm.VB!1.DA3E (CLASSIC)
YandexTrojan.GenAsa!g8z8LT30jj4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/AutoRun.RPV!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove W32/FakeFire-L?

W32/FakeFire-L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment