Fake

Win32/FakeIE.AF malicious file

Malware Removal

The Win32/FakeIE.AF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/FakeIE.AF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/FakeIE.AF?


File Info:

name: 9139362B9468AE0BD24F.mlw
path: /opt/CAPEv2/storage/binaries/0c331db8016083db5f4a94e7b8d58daf9005b5dfb33e1727495823d83e0f7161
crc32: 8B9499AE
md5: 9139362b9468ae0bd24f6fea51bdf37d
sha1: dd1fb3fe8e00249d9e9ec6840b53b59d2fc36f1d
sha256: 0c331db8016083db5f4a94e7b8d58daf9005b5dfb33e1727495823d83e0f7161
sha512: 123d0a0d0ae20dfdc284b57321d86270497f27d3aec5a030e5586e7e5db03e678ebdbc74218d021a9c88ac35476f1ed656f3db4f5b7bebc3b3131599a3f17d68
ssdeep: 12288:nor/pQfu8E4B+6z/I4NOPKdIYkCHD72bUlCKO7dUw73T1toxH:0/pou9YnrGTCHDibUlCUJH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCE46C553BA0E072C26D21B1C99BD3F566A5AC30CB3646E726A03E3D7E305C25E3963D
sha3_384: f36c6b91180cf2cba7a59d1d9ea6bf096c4a4e8492841c6198d28b662723c132f958bec1a1159521b273b404fc89d456
ep_bytes: e84e6a0000e979feffff3b0d00cb4700
timestamp: 2013-12-18 14:53:00

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Internet Explorer
FileVersion: 13, 12, 18, 2
LegalCopyright: Microsoft (C) 保留所有权利。
ProductName: Microsoft Internet Explorer
ProductVersion: 13, 12, 18, 2
Translation: 0x0804 0x03a8

Win32/FakeIE.AF also known as:

BkavW32.Common.F8232D1B
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.140561
ClamAVWin.Trojan.Fakeie-11
FireEyeGeneric.mg.9139362b9468ae0b
ALYacGen:Variant.Cerbu.140561
ZillyaDownloader.FakeIE.Win32.17
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f9501 )
K7GWTrojan ( 0040f9501 )
Cybereasonmalicious.b9468a
BitDefenderThetaGen:NN.ZexaF.36318.Pq0@aqkUNlkj
VirITTrojan.Win32.Agent4.BVXR
CyrenW32/FakeIE.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FakeIE.AF
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Multi.Generic
BitDefenderGen:Variant.Cerbu.140561
NANO-AntivirusTrojan.Win32.FakeIE.detxwo
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b2dbc5
EmsisoftGen:Variant.Cerbu.140561 (B)
BaiduWin32.Trojan.FakeIE.a
F-SecureTrojan.TR/Downloader.Gen7
DrWebTrojan.FakeIE.10
VIPREGen:Variant.Cerbu.140561
McAfee-GW-EditionBehavesLike.Win32.Adware.jh
SophosML/PE-A
GDataGen:Variant.Cerbu.140561
AviraTR/Downloader.Gen7
Antiy-AVLTrojan/Win32.SGeneric
XcitiumTrojWare.Win32.TrojanDownloader.FakeIE.FAK@5t4qvw
ArcabitTrojan.Cerbu.D22511
SUPERAntiSpywareTrojan.Agent/Gen-FakeMS
ZoneAlarmHEUR:Trojan.Multi.Generic
MicrosoftTrojanDownloader:Win32/FakeIE.A
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAlert.R120601
McAfeeGenericRXAA-AA!9139362B9468
MAXmalware (ai score=88)
VBA32TrojanDownloader.FakeIE
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingDownloader.FakeIE!8.198 (TFE:5:cU3dmodIL9T)
YandexTrojan.FakeIE!4V8COijcukQ
IkarusTrojan-Spy.Win32.Delf
MaxSecureTrojan.Malware.4388231.susgen
FortinetW32/FakeIE.AF!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/FakeIE.AF?

Win32/FakeIE.AF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment