Threat Database Trojans Trojan.FakeMS.F

Trojan.FakeMS.F

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,451
Threat Level: 80 % (High)
Infected Computers: 47,471
First Seen: August 13, 2021
Last Seen: June 30, 2026
OS(es) Affected: Windows

The detection of Trojan.FakeMS.F on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system. It's crucial to approach this situation with a clear understanding of the risks and the necessary actions to mitigate them.

What Is Trojan.FakeMS.F?

Trojan.FakeMS.F is identified as a Trojan-type threat. Trojans are malicious programs that can infiltrate your system by disguising themselves as legitimate software. Once inside, they can cause a variety of problems, including data theft, system compromise, and the installation of additional malware. The name Trojan.FakeMS.F suggests it may mimic or claim to be a Microsoft-related product or service to deceive users, but without specific details, it's essential to focus on general removal and security practices.

How Trojan.FakeMS.F Operates

Trojan.FakeMS.F, like other Trojans, operates by exploiting vulnerabilities in your system's security or by tricking users into installing it. Once installed, it can execute a range of malicious activities. These can include stealing sensitive information, downloading and installing additional malware, and providing unauthorized access to your system. The exact operations of Trojan.FakeMS.F can vary, but the end goal is typically to compromise your system's security and privacy for the benefit of the attackers.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow system performance, and unfamiliar programs or icons on your desktop. You might also notice that your browser settings have changed without your input, or you're being redirected to unwanted websites. In some cases, you might not notice any symptoms at all, which is why regular system scans with reputable antivirus software are crucial.

How to Remove Trojan.FakeMS.F

  1. Enter Safe Mode with Networking: This will allow you to use the internet while limiting the functionality of the malware, making it easier to remove. To do this, restart your computer and immediately start tapping the F8 key. Select Safe Mode with Networking from the Advanced Boot Options menu.
  2. Conduct a Full Scan with a Reputable Tool: Use a trusted antivirus program, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan.FakeMS.F and any other malware that might be present.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove anything that looks suspicious or unfamiliar. Be cautious, as some legitimate programs might have similar names to malware.
  4. Reset Your Browsers: Resetting your browsers (Chrome, Firefox, Edge, etc.) to their default settings can help remove any malicious extensions or settings changes caused by the Trojan. You can usually find this option in the browser's settings or preferences menu.
  5. Reboot and Re-scan: After completing the above steps, restart your computer in normal mode and perform another scan with your antivirus software to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.FakeMS.F from your system requires careful and methodical steps to ensure that the malware is fully eradicated. It's also a good opportunity to review your system's security and take preventative measures to avoid future infections. Keeping your operating system, software, and antivirus programs up to date, being cautious with emails and downloads, and regularly scanning your system can significantly reduce the risk of malware infections. If you're unsure about any part of the removal process, consider consulting with a professional to ensure your system's security and integrity are maintained.

Analysis Report

General information

Family Name: Trojan.FakeMS.F
Signature status: No Signature

Known Samples

MD5: 11808893677d922d47fc2df54b613511
SHA1: 843813930d74ebfed0581f3e8e463c8efeee2c86
SHA256: B5C68C9870A425A2CA55CB34E788472E21BF4493E3097BC0A7FA14ACC3F7BE85
File Size: 211.34 KB, 211336 bytes
MD5: b864460fe19a3e5e096326906c9c8f1f
SHA1: acd5b0ccb22218c219279df1651dd4eb8f0b5d8d
SHA256: 762939A4B49D666E6EF1C0342B41B253D56E3D8876A18388D3DDDED523D2D469
File Size: 40.45 KB, 40448 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.0.0.9
  • 0.0.0.0
Company Name Hitech Systems, Inc.
File Description Virtual Panic Button
File Version
  • 1.0.0.9
  • 0.0.0.0
Internal Name
  • faaa.secure.exe
  • VPB.exe
Legal Copyright Copyright © 2025 Hitech Systems, Inc.
Original Filename
  • faaa.secure.exe
  • VPB.exe
Product Name SafetyNet Virtual Panic Button
Product Version
  • 1.0.0.9
  • 0.0.0.0

Digital Signatures

Signer Root Status
Hitech Systems, Inc SSL.com Code Signing Intermediate CA RSA R1 Self Signed

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 64
Potentially Malicious Blocks: 1
Whitelisted Blocks: 63
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.FakeMS.L
  • MSIL.Gamehack.BAVB
  • MSIL.Gamehack.BAVG
  • MSIL.Gamehack.BAVH
  • MSIL.Gamehack.BAVI
Show More
  • MSIL.Gamehack.HM
  • MSIL.Gamehack.O
  • MSIL.Gamehack.OI

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134098385291550907.2320.defaultappdomain.843813930d74ebfed0581f3e8e463c8efeee2c86_0000211336 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134237598263702624.2612.defaultappdomain.acd5b0ccb22218c219279df1651dd4eb8f0b5d8d_0000040448 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_0ylobrkg.pkj.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_43g0wkvb.3rd.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_tycsxire.wkc.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_wqrplip1.cdx.ps1 Generic Write,Read Attributes
c:\windows\system32\systema.ps1 Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory

5 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent

Related Posts

Trending

Most Viewed

Loading...