Fake Trojan

How to remove “Trojan.FakeMBAM”?

Malware Removal

The Trojan.FakeMBAM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeMBAM virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.FakeMBAM?


File Info:

name: 633A1243D95363F29ECA.mlw
path: /opt/CAPEv2/storage/binaries/81c90180ae440ae2684eb760196458faf482b3a0834ef6797453a8d4ed255c1c
crc32: 5942ECCE
md5: 633a1243d95363f29eca9a232dbc6811
sha1: 510441f01ed4e13353eb29a4e15678c5ecbe5cdf
sha256: 81c90180ae440ae2684eb760196458faf482b3a0834ef6797453a8d4ed255c1c
sha512: 7a144602ca96197509b4adc17f65bd188a33f1904ea18ee461255f9937723be82ad96af8c480d878aa8fa624a5752be75f8f6c5e96b66943d6913a2fe53ff952
ssdeep: 24576:wHEQfTX/W61OpeAXy0Tog7vp7sTAJmdMk9CUeuQ5p3h3u1qc:whtJ7gTp7yAJK5qc
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T179B52A035A8B0E75DDC27BB461CB633B9734EE30CA2A9B7FF609C53599532C4681A742
sha3_384: c474ae472fcb562265f6ad19f96d3145da5e0cbd0b60a4138e32edcdce4fdc750b56689d653cd8322a3f43ae540c1779
ep_bytes: 83ec1cc7042401000000ff1508135100
timestamp: 2022-06-13 10:02:37

Version Info:

0: [No Data]

Trojan.FakeMBAM also known as:

MicroWorld-eScanGen:Variant.Jaik.80546
FireEyeGen:Variant.Jaik.80546
ALYacGen:Variant.Jaik.80546
MalwarebytesTrojan.FakeMBAM
BitDefenderThetaGen:NN.ZexaF.34712.r!Z@ayrysQ
CyrenW32/Kryptik.GTB.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HPFH
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Jaik.80546
TencentTrojan-Psw.Win32.Reline.16000435
Ad-AwareGen:Variant.Jaik.80546
EmsisoftGen:Variant.Jaik.80546 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Jaik.80546
AhnLab-V3Infostealer/Win.AntiAV.R497427
CylanceUnsafe
APEXMalicious
RisingSpyware.Convagent!8.12330 (TFE:dGZlOgVRZU26bfbcCg)

How to remove Trojan.FakeMBAM?

Trojan.FakeMBAM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment