Fake Trojan

Trojan.FakeFlash malicious file

Malware Removal

The Trojan.FakeFlash is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeFlash virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers

How to determine Trojan.FakeFlash?


File Info:

name: E6DF4BEC839A53943A9E.mlw
path: /opt/CAPEv2/storage/binaries/f8a033b34d92edc1d3e430b74cbbe4f13991c22fd0412d3bd30c13a2dc8b65e2
crc32: FB1F647B
md5: e6df4bec839a53943a9e3639bd554a78
sha1: 6229f140306fb795e29eab7d61654c19b0675a5b
sha256: f8a033b34d92edc1d3e430b74cbbe4f13991c22fd0412d3bd30c13a2dc8b65e2
sha512: 90732894fb49001cca482c1a6c868ca5bad22ede5168bdce5e7b40b7a0b8f3ed0334efff76e8e7eceb294784fc7ab05e5aeb2ce93bba16986dabd89211424e6f
ssdeep: 6144:Ye34/zR0XeCFuWiL77QFuWTgtZ43vbahoTeallT5i2e/dC5Tj2ZkmNFuWbyaS+IC:SGLuWc7uuWc03vbQQeaFj2JuWbybHE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF942302D3E8C47BD322A33214965BD1EB774947C2608BA79F651F5E6636ED38207B32
sha3_384: d91de075f87c46b766b6202ac46c8deeb1233c965004b3cd86a4f5353dffa86b080f2b57e7c190623b59fdc1e67a8df6
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

Trojan.FakeFlash also known as:

LionicAdware.Win32.Coupons.2!c
DrWebJS.IFrame.558
MicroWorld-eScanDropped:Trojan.Agent.JS.GR
FireEyeDropped:Trojan.Agent.JS.GR
McAfeeGeneric.eni
CylanceUnsafe
ZillyaTrojan.Agent.Win32.883226
SangforPUP.Win32.Vigua.A
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanClicker:Win32/Coupons.a3873a81
K7GWSpyware ( 004915271 )
K7AntiVirusSpyware ( 004915271 )
ESET-NOD32JS/TrojanClicker.Agent.NFJ.Gen
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Coupons.v
BitDefenderDropped:Trojan.Agent.JS.GR
NANO-AntivirusTrojan.Script.Autoit.drljfy
AvastOther:Malware-gen [Trj]
TencentWin32.Adware.Coupons.Ammh
Ad-AwareDropped:Trojan.Agent.JS.GR
SophosMal/Generic-R
ComodoMalware@#agoao6afmev9
BaiduMulti.Threats.InArchive
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.19B414
McAfee-GW-EditionGeneric.eni
EmsisoftDropped:Trojan.Agent.JS.GR (B)
GDataDropped:Trojan.Agent.JS.GR
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwNS.281B
ArcabitTrojan.Agent.JS.GR
ViRobotTrojan.Win32.Z.Agent.437806
MicrosoftTrojan:Win32/Occamy.CF8
ALYacDropped:Trojan.Agent.JS.GR
VBA32AdWare.Coupons
MalwarebytesTrojan.FakeFlash
TrendMicro-HouseCallTROJ_SPNR.19B414
SentinelOneStatic AI – Suspicious PE
FortinetJS/Moat.7E225791!tr
AVGOther:Malware-gen [Trj]
Cybereasonmalicious.c839a5

How to remove Trojan.FakeFlash?

Trojan.FakeFlash removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment