Fake Trojan

Trojan.FakeMS.SVSGen removal guide

Malware Removal

The Trojan.FakeMS.SVSGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeMS.SVSGen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan.FakeMS.SVSGen?


File Info:

crc32: 9A67CF1B
md5: bc4d2f84a6ce49f06a6be32ccfaa1630
name: BC4D2F84A6CE49F06A6BE32CCFAA1630.mlw
sha1: 6f43fe80806a3fe5c866c0b63cc5b105a85d0e75
sha256: 00b701e3ef29912c1fcd8c2154c4ae372cfe542cfa54ffcce9fb449883097cec
sha512: 5af868507abda4c08a5b6bc5ded5a573edcc1133507718e49007d0ade0565a4c42156d9b3d9fff1dfd7b298e37c1705cc87329ba4d26e62b18da07e5bc1a02e6
ssdeep: 12288:ECVrN8KTdfZgMvDoWQDUEOHcKReREQbN3x2aVD+p:EkNPTdfZfJVHcKPf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013
InternalName: WinUG
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: WinUG
SpecialBuild:
ProductVersion: 6.1.7600.16414
FileDescription: Aplication software
OriginalFilename: WinUG.exe
joker: 0x0409 0x04b0

Trojan.FakeMS.SVSGen also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00577e3f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.SchoolBoy
ALYacTrojan.GenericKD.34749370
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2597039
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.627bdf8e
K7GWTrojan ( 00577e3f1 )
Cybereasonmalicious.4a6ce4
CyrenW32/Trojan.QKTS-3815
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HKQI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.SchoolBoy.gen
BitDefenderTrojan.GenericKD.34749370
NANO-AntivirusTrojan.Win32.SchoolBoy.iaqvyj
MicroWorld-eScanTrojan.GenericKD.34749370
Ad-AwareTrojan.GenericKD.34749370
ComodoMalware@#3edoo7a85t3qw
BitDefenderThetaGen:NN.ZexaCO.34738.Bu0@aSYXGjpO
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WF921
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.bc4d2f84a6ce49f0
EmsisoftTrojan.GenericKD.34749370 (B)
JiangminTrojan.Schoolboy.hn
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.qkglq
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA00
ArcabitTrojan.Generic.D2123BBA
AegisLabTrojan.Win32.SchoolBoy.4!c
ZoneAlarmHEUR:Trojan.Win32.SchoolBoy.gen
GDataTrojan.GenericKD.34749370
AhnLab-V3Malware/Win32.Generic.C4123306
McAfeeRDN/Generic.hbg
MAXmalware (ai score=100)
VBA32BScope.Trojan.Kasidet
MalwarebytesTrojan.FakeMS.SVSGen
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WF921
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.10640424.susgen
FortinetW32/Kryptik.HGCE!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.FakeMS.SVSGen?

Trojan.FakeMS.SVSGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment