Fake Trojan

Trojan.FakeVer removal tips

Malware Removal

The Trojan.FakeVer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeVer virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Creates a copy of itself

Related domains:

azase123.f3322.net

How to determine Trojan.FakeVer?


File Info:

crc32: 8C11B319
md5: d5882222159cbe3457f82052d924a180
name: D5882222159CBE3457F82052D924A180.mlw
sha1: dd7c3f6f2d16e5b89261da77304b0951dcfef236
sha256: e8757ae0cde2c3f7445ff903b76ef6d580f65ec270b603cf19aff14c0f8f8900
sha512: 202ad2f5e3ae6354d870729544f1cec62397c784f848e979027c8d6c3283d746ecf7d5f177144fc5df74caad822d08c2791c3dcc55f3e6cfe30562127e1a868b
ssdeep: 768:CKsL+/5N7hF5sxUuhQ0L4Ag2KZtB4orV9qX6LpFxrl9lC3:CczhXR1AW5TvR92idrtq
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: xa9 2006-2010 Virage Logic/Sonic Focus
InternalName: SonicMaster
FileVersion: 1.00.0003
CompanyName: Virage Logic Corporation/Sonic Focus
ProductName: ASUS Sonic Master
ProductVersion: 1.00.0003
FileDescription: ASUS Sonic Master
OriginalFilename: SonicMaster.exe

Trojan.FakeVer also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AgentWDCR.ABWA
FireEyeGeneric.mg.d5882222159cbe34
CAT-QuickHealTrojan.Agent
Qihoo-360Win32/Backdoor.Zegost.HwsBArsA
ALYacTrojan.AgentWDCR.ABWA
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.20045
AegisLabTrojan.Win32.Staser.4!c
SangforMalware
K7AntiVirusTrojan ( 0049fe3c1 )
BitDefenderTrojan.AgentWDCR.ABWA
K7GWTrojan ( 0049fe3c1 )
Cybereasonmalicious.2159cb
BaiduWin32.Trojan.Farfli.bd
CyrenW32/KillAV.AU.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
AvastOther:Malware-gen [Trj]
ClamAVWin.Trojan.Generic-6305873-0
KasperskyTrojan.Win32.Agent.xaepsv
AlibabaBackdoor:Win32/Staser.7a11d68f
NANO-AntivirusTrojan.Win32.Dwn.denvkl
ViRobotTrojan.Win32.Agent.103748[UPX]
RisingBackdoor.Zegost!8.177 (KTSE)
Ad-AwareTrojan.AgentWDCR.ABWA
TACHYONTrojan-PWS/W32.WebGame.98304.MI
EmsisoftTrojan.AgentWDCR.ABWA (B)
ComodoTrojWare.Win32.Agent.PDSB@4q3i1w
F-SecureTrojan.TR/Proxy.BU
DrWebTrojan.DownLoader21.62782
VIPREWin32.Malware!Drop
TrendMicroBKDR_FARFLI.SMP
McAfee-GW-EditionGenericRXER-KZ!D5882222159C
SophosMal/Generic-R + Troj/Zegost-JJ
IkarusTrojan.Win32.KillAV
JiangminTrojan/PSW.Magania.bgyu
WebrootW32.Malware.Gen
AviraTR/Proxy.BU
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Heur.KVM005.a.(kcloud)
MicrosoftBackdoor:Win32/Zegost.DA
ArcabitTrojan.AgentWDCR.ABWA
ZoneAlarmTrojan.Win32.Agent.xaepsv
GDataWin32.Trojan.Agent.O79DEO
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Farfli.R137875
Acronissuspicious
McAfeeGenericRXER-KZ!D5882222159C
MAXmalware (ai score=87)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.FakeVer
PandaTrj/WLT.F
ZonerTrojan.Win32.32102
ESET-NOD32Win32/Farfli.BAB
TrendMicro-HouseCallBKDR_FARFLI.SMP
TencentTrojan.Win32.Csfrsys.a
YandexTrojan.GenAsa!qh3xbjhHOAI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Farfli.BAB!tr
BitDefenderThetaAI:Packer.711E30AC1F
AVGOther:Malware-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.FakeVer?

Trojan.FakeVer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment