Fake Trojan

Trojan.FakeSteam information

Malware Removal

The Trojan.FakeSteam is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeSteam virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.FakeSteam?


File Info:

name: 8E0BB0D4B8DCC982C071.mlw
path: /opt/CAPEv2/storage/binaries/c64a890419898ecea9ab6816c4f966eef513a9133dc41493a6a2ce61df086355
crc32: 47E7B34C
md5: 8e0bb0d4b8dcc982c0714429bf8b2189
sha1: ebc0e1d8d9fcd9f2e6e99f02e6bc1cafc5d46b8c
sha256: c64a890419898ecea9ab6816c4f966eef513a9133dc41493a6a2ce61df086355
sha512: 651b6915b6be92b0cba0df3b1533b6cadcd97e47bc1d0f574a697757f0bd2fb5bd5d80201572c1acb0f88e9742fcb644884532b51037419eba2ac45eeb080fa2
ssdeep: 24576:PuFyTv4xU2skYotRHddhtxfmmAGHjk6WAYZJ6bG27sceTDMEL9Wr5S1SDNscRmru:Pumv4x5sx4TvxfbDkJLZASzlL9WM1SD5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FA15BF252A5BD5EACF9364350178EE46942932712A2F74727F500BEA4B337C1DAD0F8E
sha3_384: 6dac8fd04fbeae9742116908318775114dc273f02a316cf6f838942a0e32f89a8ff160c3e866d9d80c9d339558afc682
ep_bytes: e82d050000e974feffff558beceb0dff
timestamp: 2021-09-06 16:16:05

Version Info:

CompanyName: Valve Corporation
FileDescription: Steam
FileVersion: 1, 0, 0, 2
InternalName: steam
LegalCopyright: Copyright (C) 2021 Valve Corporation
OriginalFilename: steam.exe
ProductName: Steam
ProductVersion: 1, 0, 0, 2
Translation: 0x0409 0x04b0

Trojan.FakeSteam also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.l!c
MicroWorld-eScanGen:Variant.Fragtor.16144
FireEyeGeneric.mg.8e0bb0d4b8dcc982
McAfeeGenericRXPZ-SG!8E0BB0D4B8DC
MalwarebytesTrojan.FakeSteam
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34182.5u2@ai4Z3Oli
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R067C0WIH21
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Fragtor.16144
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.11d9cdc1
EmsisoftGen:Variant.Fragtor.16144 (B)
TrendMicroTROJ_GEN.R067C0WIH21
McAfee-GW-EditionGenericRXPZ-SG!8E0BB0D4B8DC
SophosMal/Generic-S
WebrootW32.Trojan.Gen
AviraTR/Spy.Stealer.nbtoz
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Fragtor.16144
AhnLab-V3Trojan/Win.Generic.R440642
VBA32TrojanSpy.Stealer
ALYacGen:Variant.Fragtor.16144
MAXmalware (ai score=86)
CylanceUnsafe
YandexTrojanSpy.Stealer!duzWS8NbqEE
FortinetW32/Kryptik.FJUK!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A

How to remove Trojan.FakeSteam?

Trojan.FakeSteam removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment