Fake Trojan

Trojan:Win32/FakeFolder.EA!MTB removal

Malware Removal

The Trojan:Win32/FakeFolder.EA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FakeFolder.EA!MTB virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/FakeFolder.EA!MTB?


File Info:

name: 30E1185379670F3BF947.mlw
path: /opt/CAPEv2/storage/binaries/b67017fbcab8fa7a499b565261782260b03f52e44721dc67d6b4b0980726e146
crc32: 6A8DD28B
md5: 30e1185379670f3bf9475c33050f7a6b
sha1: 6c93fb82b8ef9569a02e39642f40da1673f6cb3e
sha256: b67017fbcab8fa7a499b565261782260b03f52e44721dc67d6b4b0980726e146
sha512: ea61408ce814be4aab980fe37a1f853ae2a561c019859705790579af585bef5fcf2517b406f7bd423f4693b56c28e22f1bafb7febf0e631e10b7bd9e1838df58
ssdeep: 24576:2G2s/vZn2WTiFYCcQj/unPKa6oyzqxjvZYF:5p26yVzqBvm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2057D53B3D7D0B2DFA626F3D6B49376193AB834173C89CB7390282DE8906C16A35359
sha3_384: 50977664c71ea8e965b181d456791ea1036f313e472237802c2c751b454d0c67335c31a4e07c3e69b8aac238587b20bd
ep_bytes: e8505e0000e989feffffcccccc568b44
timestamp: 2019-11-24 04:49:56

Version Info:

0: [No Data]

Trojan:Win32/FakeFolder.EA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.AutoHotKey.Agent.A.A5FEBAC5
ClamAVWin.Malware.Misc-9950733-0
FireEyeGeneric.AutoHotKey.Agent.A.A5FEBAC5
CAT-QuickHealPUA.AgentPMF.S24861111
McAfeeTrojan-FUCG!30E118537967
SangforSuspicious.Win32.Save.ins
VirITTrojan.Win32.Generic.CDD
CyrenW32/FakeFolder.T.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.AHK.G suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.AHRun.gen
BitDefenderGeneric.AutoHotKey.Agent.A.A5FEBAC5
AvastFileRepMalware [Misc]
RisingMalware.FakeFolder/ICON!1.D519 (CLASSIC)
EmsisoftGeneric.AutoHotKey.Agent.A.A5FEBAC5 (B)
F-SecureHeuristic.HEUR/AGEN.1319416
VIPREGeneric.AutoHotKey.Agent.A.A5FEBAC5
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
SophosTroj/AutoHK-N
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1EA9LG1
AviraHEUR/AGEN.1319416
MAXmalware (ai score=88)
ArcabitGeneric.AutoHotKey.Agent.A.A5FEBAC5
ZoneAlarmUDS:Trojan.Win32.AHRun.gen
MicrosoftTrojan:Win32/FakeFolder.EA!MTB
GoogleDetected
AhnLab-V3Malware/Win.Generic.C4432452
ALYacGeneric.AutoHotKey.Agent.A.A5FEBAC5
TACHYONTrojan/W32.Agent.824832.CC
Cylanceunsafe
PandaTrj/CI.A
TencentTrojan.Win32.Agent.kb
IkarusPUA.AHK
FortinetRiskware/FakeFolder
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/FakeFolder.EA!MTB?

Trojan:Win32/FakeFolder.EA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment