Threat Database Trojans Trojan.FakeMS.B

Trojan.FakeMS.B

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 66
First Seen: December 8, 2012
Last Seen: December 16, 2025
OS(es) Affected: Windows

The detection of Trojan.FakeMS.B indicates that your system has been compromised by a potentially harmful piece of software. This report aims to provide you with a comprehensive understanding of the threat, its operational methods, symptoms of infection, and most importantly, guidance on how to remove it from your system.

What Is Trojan.FakeMS.B?

Trojan.FakeMS.B is identified as a Trojan-type threat, which means it is designed to deceive users into installing it on their systems by disguising itself as legitimate software. Trojans are known for their ability to create backdoors on infected systems, allowing attackers to access and control the system remotely. This can lead to a variety of malicious activities, including data theft, installation of additional malware, and exploitation of system resources for spamming or cryptocurrency mining.

How Trojan.FakeMS.B Operates

Once installed, Trojan.FakeMS.B can operate in various ways, depending on its intended purpose by its creators. It may start by scanning the system for sensitive information such as login credentials, credit card numbers, or personal data. It can also install additional malware or create a backdoor to allow remote access to the system. The Trojan may communicate with its command and control servers to receive updates or send stolen data. Its operational methods can vary, making it a versatile and potentially dangerous threat.

Symptoms of Infection

Symptoms of a Trojan.FakeMS.B infection can be subtle and may not always be immediately apparent. However, common indicators include unusual system behavior such as slowed performance, frequent crashes, or the appearance of unwanted programs or toolbars in your web browser. You might also notice changes in your system settings or the presence of suspicious processes running in the background. In some cases, the Trojan may trigger pop-ups or display fake alerts to deceive the user into performing certain actions that could further compromise the system.

How to Remove Trojan.FakeMS.B

  1. Enter Safe Mode with Networking: This will prevent the Trojan from loading and allow you to perform removal steps without interference. Restart your computer and press the key to enter safe mode (this varies by system but is often F8).
  2. Perform a Full Scan with a Reputable Tool: Utilize a reputable anti-malware tool, such as SpyHunter, to scan your system thoroughly. These tools are designed to detect and remove malware, including Trojans like Trojan.FakeMS.B.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you do not recognize or that were installed around the time the infection was detected.
  4. Reset Your Web Browsers: Trojans often affect web browsers, so resetting Chrome, Firefox, Edge, or any other browser you use can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot and Re-scan: After completing the above steps, reboot your system to ensure all changes take effect, and then perform another scan to verify that the Trojan has been successfully removed.

Conclusion

Removing Trojan.FakeMS.B requires careful and methodical steps to ensure the malware is completely eradicated from your system. It's crucial to stay vigilant and keep your antivirus and anti-malware tools updated to protect against future threats. Regularly backing up important data and being cautious when installing software or clicking on links can also help prevent infections. If you're unsure about any part of the removal process, consider consulting with a professional to ensure your system is fully secured and protected.

Analysis Report

General information

Family Name: Trojan.FakeMS.B
Signature status: No Signature

Known Samples

MD5: a69e9f02881d423e8494ceee0e90208c
SHA1: e5a39346b033a45a9f2c2a7fc86e2f1db1ceb7d0
SHA256: EDD28BAF3925E8CD13C2564A1900178EFC3FC4542244768AC1726C96BBED502F
File Size: 32.26 KB, 32256 bytes
MD5: 480a8f17d258492ddf537badfd758831
SHA1: 10e152c2fdc8fb4157bb0b68a37c063ffbf48bfb
SHA256: C07C98AC65660A9DF9006D87290CDD358B7D57662C657FF3D183C80C81C0C38E
File Size: 28.16 KB, 28160 bytes
MD5: 3b87a560205b878501b5a60fb598e152
SHA1: 414c20b11604b16eabef24d7df73cace21acd6c4
SHA256: 611F9633F42ADFE1752293AD5D1709FA7135C4FCD7F6F99A66C0601C4D24AF0C
File Size: 30.72 KB, 30720 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • MAZ_MX_LAPTOP.exe
  • Script_Conexao_SSH.exe
  • unirdominio1.exe
Original Filename
  • MAZ_MX_LAPTOP.exe
  • Script_Conexao_SSH.exe
  • unirdominio1.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 52
Potentially Malicious Blocks: 0
Whitelisted Blocks: 52
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.FSDA
  • MSIL.FakeMS.HK
  • MSIL.FakeMS.LA
  • MSIL.FakeMS.QA
  • MSIL.FakeMS.QF
Show More
  • MSIL.FakeMS.QH
  • MSIL.FakeMS.QL

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134038039460099321.288.defaultappdomain.e5a39346b033a45a9f2c2a7fc86e2f1db1ceb7d0_0000032256 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134102366912553472.1612.defaultappdomain.10e152c2fdc8fb4157bb0b68a37c063ffbf48bfb_0000028160 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134104430028761726.8676.defaultappdomain.414c20b11604b16eabef24d7df73cace21acd6c4_0000030720 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_1meg5bog.xb3.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_5pf015ty.nbv.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_bhpzvect.m4y.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_gn1eu3bb.vjg.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_hzxrygrx.wm1.ps1 Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\__psscriptpolicytest_xcli0ldl.yuv.ps1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\control\lsa::netjoinlegacyaccountreuse  RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
Show More
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange

15 additional items are not displayed above.

User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSASocket
  • WSAStartup
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • gethostname
  • setsockopt

Trending

Most Viewed

Loading...