Fake Trojan

Trojan:Win32/FakeFolder!MTB information

Malware Removal

The Trojan:Win32/FakeFolder!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FakeFolder!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/FakeFolder!MTB?


File Info:

name: 6BBE44B13501281C2521.mlw
path: /opt/CAPEv2/storage/binaries/4b3e8c5c5841c9aba73b6656933b9a6991fd9d3a81a5315921b833f907cb0529
crc32: C64F4503
md5: 6bbe44b13501281c25217d04be8660fd
sha1: 601ea57295fc8d50c60a58a43f559ebff5739294
sha256: 4b3e8c5c5841c9aba73b6656933b9a6991fd9d3a81a5315921b833f907cb0529
sha512: a5eaa3ab112048bc6539e5f093348bb2436618c8f57c27574c83d7ee92cd48a443475ebbafd2ca135535c2217579cb53630b686d9eb73e1d2c33bf2a6af73f07
ssdeep: 49152:eCGLOraLdXThGljn0zLJbzW7X8b4UvuHFFyycqUZx9QwyPOxyU4mi1HrsISuYwMh:eJQaLXTZx9lyUZJ0HArfMgHHIpP3Vde
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5E57BE1B501F035DDE908B7EBBE49B28D6C8E15372A38E3A1F87489C1761E1613925F
sha3_384: 7058d42e43a78a0513cfe99173154adab1b55487c1590475af232f4d01b46840cc3e03bde5b8235b93eaf8d4778eecd3
ep_bytes: e872030000e936fdffff8bff558bec8b
timestamp: 2008-11-10 09:40:35

Version Info:

0: [No Data]

Trojan:Win32/FakeFolder!MTB also known as:

LionicWorm.Python.Generic.o!c
AVGFileRepMalware [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.FKUK
FireEyeGeneric.mg.6bbe44b13501281c
McAfeeGenericRXAA-AA!6BBE44B13501
CylanceUnsafe
VIPRETrojan.Agent.FKUK
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d311e1 )
AlibabaWorm:Python/Agent.73a00ea9
K7GWTrojan ( 004d311e1 )
Cybereasonmalicious.295fc8
SymantecML.Attribute.HighConfidence
ESET-NOD32Python/Agent.K
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Worm.Python.Generic
BitDefenderTrojan.Agent.FKUK
NANO-AntivirusTrojan.Py2Exe.PyAgent.eqmocu
AvastFileRepMalware [Trj]
TencentWorm.Win32.Python.ya
Ad-AwareTrojan.Agent.FKUK
EmsisoftTrojan.Agent.FKUK (B)
DrWebPython.Siggen.13
ZillyaWorm.Agent.Win32.42197
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Agent.FKUK
AviraTR/Worm.Gen
MAXmalware (ai score=87)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Agent.FKUK
MicrosoftTrojan:Win32/FakeFolder!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Skeeyah.R208255
Acronissuspicious
ALYacTrojan.Agent.FKUK
TACHYONTrojan/W32.Blakamba.3022848
VBA32Worm.Occamy
MalwarebytesWorm.Agent
RisingTrojan.Generic@AI.87 (RDMK:gVQJGxGpZjYh4thmtd9GGQ)
YandexTrojan.Worm!rH3RF18gmPw
IkarusWorm.Python.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.K!tr

How to remove Trojan:Win32/FakeFolder!MTB?

Trojan:Win32/FakeFolder!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment