Fake Trojan

Trojan.FakeMS.Gen removal instruction

Malware Removal

The Trojan.FakeMS.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeMS.Gen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • Drops a binary and executes it
  • Looks up the external IP address
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

whatismyipaddress.com

How to determine Trojan.FakeMS.Gen?


File Info:

crc32: AE6FC7CB
md5: 37dccc58fe35b28dfc3480dafb66dd50
name: dashboard_hacking.exe
sha1: c910337fd8f430d104bf0b8eea3fe4a76590434b
sha256: f2c2061b4f1a4946600187fce748057886a2a9a74d83b06f2f201ab98e0ac044
sha512: b4f135f355f56566c75809ac69884956c7b9a9873027114bb8913461959dd2063c735d34a1f002adac4f5bbf9c08aebe2d56539f41669d80293920cf37c66a53
ssdeep: 24576:yfxFa2hS6cxvJMOQMySUZ/+UVeCMEcZLwRlQaohuaPjX0C9bR0zC:yfxvhS6cv5QMySUZ/+UsfZcMLEaezC
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2013
Assembly Version: 1.0.0.0
InternalName: Microsoft.exe
FileVersion: 1.0.0.0
ProductName: Microsoft
ProductVersion: 1.0.0.0
FileDescription: Microsoft
OriginalFilename: Microsoft.exe

Trojan.FakeMS.Gen also known as:

MicroWorld-eScanGen:Variant.MSILPerseus.169316
FireEyeGeneric.mg.37dccc58fe35b28d
ALYacGen:Variant.MSILPerseus.169316
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00503fce1 )
BitDefenderGen:Variant.MSILPerseus.169316
K7GWTrojan ( 00503fce1 )
Cybereasonmalicious.8fe35b
F-ProtW32/MSIL_Agent.CO.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Unsafe-6623001-0
GDataGen:Variant.MSILPerseus.169316
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Autoruner.dchwbt
RisingSpyware.Agent!8.C6 (CLOUD)
Ad-AwareGen:Variant.MSILPerseus.169316
EmsisoftGen:Variant.MSILPerseus.169316 (B)
ComodoMalware@#gy0chtzur6af
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.PWS.Stealer.15120
Invinceaheuristic
McAfee-GW-EditionGeneric BackDoor.adv
Trapminemalicious.high.ml.score
SophosMal/Boom105-B
IkarusWorm.MSIL.Autorun
CyrenW32/MSIL_Agent.CO.gen!Eldorado
WebrootW32.Malware.gen
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/MSIL.Packed.Confuser.P
Endgamemalicious (high confidence)
ArcabitTrojan.MSILPerseus.D29564
SUPERAntiSpywareTrojan.Agent/Gen-Tester
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Dynamer!rfn
AhnLab-V3Trojan/Win32.Agent.R98018
McAfeeGeneric BackDoor.adv
MAXmalware (ai score=99)
MalwarebytesTrojan.FakeMS.Gen
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.DF
TencentMsil.Worm.Autorun.Lmlg
YandexTrojan.Agent!bxVw/H0mFBQ
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/MsilKlog.D!tr
BitDefenderThetaGen:NN.ZemsilF.34090.ir0@amREdnn
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.ab3

How to remove Trojan.FakeMS.Gen?

Trojan.FakeMS.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment