Threat Database Trojans Trojan.MicroFake.A

Trojan.MicroFake.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,868
Threat Level: 80 % (High)
Infected Computers: 4,173
First Seen: November 3, 2018
Last Seen: May 23, 2026
OS(es) Affected: Windows

The detection of Trojan.MicroFake.A indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to deceive and manipulate users, often by disguising itself as legitimate software or by exploiting vulnerabilities in the system. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is Trojan.MicroFake.A?

Trojan.MicroFake.A is a type of Trojan horse, a malicious program that masquerades as legitimate software. The name itself does not directly indicate a specific malware family, but rather a generic classification of the threat. Trojans are known for their ability to sneak into a system without being detected, often by exploiting user trust or system vulnerabilities. Once inside, they can cause a range of problems, from stealing sensitive information to disrupting system operations.

How Trojan.MicroFake.A Operates

Like other Trojans, Trojan.MicroFake.A operates by deceiving users into installing it on their systems. This can happen through various means, such as downloading software from untrusted sources, clicking on malicious links, or opening infected email attachments. Once installed, the Trojan can communicate with its creators, allowing them to remotely control the infected system, steal data, or install additional malware. The exact mechanisms of Trojan.MicroFake.A's operation are not specified, but its presence indicates a significant security risk.

Symptoms of Infection

Symptoms of a Trojan.MicroFake.A infection can vary, but common signs include unexpected system behavior, such as slow performance, frequent crashes, or unfamiliar programs appearing on the system. Users might also notice unusual network activity, changes in browser settings, or the presence of unwanted toolbars and extensions. In some cases, the infection might not exhibit noticeable symptoms immediately, making it crucial to regularly scan the system for malware.

How to Remove Trojan.MicroFake.A

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more straightforward removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components of the Trojan.
  3. Uninstall any suspicious programs or applications that you do not recognize or no longer need. Be cautious and ensure you are removing the correct programs to avoid damaging your system.
  4. Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the system is clean and the Trojan has been successfully removed.

Conclusion

The detection and removal of Trojan.MicroFake.A require immediate attention to prevent further damage to your system and protect your personal data. By understanding how Trojans operate and following the removal steps outlined, you can effectively eliminate this threat. It's also crucial to adopt preventive measures, such as regularly updating your operating system and software, using strong antivirus protection, and being cautious when downloading software or clicking on links from unknown sources. Remember, vigilance and proactive security practices are key to maintaining a secure computing environment.

Analysis Report

General information

Family Name: Trojan.MicroFake.A
Signature status: No Signature

Known Samples

MD5: 5892d43bc2895a665abff11d56618eae
SHA1: b75cda76995c677af2c7e75f9003c22175045a11
SHA256: D8A07790280C76D04F97311B84365DB96EB6B988DFC84CE79044BADB5E028CE7
File Size: 74.24 KB, 74240 bytes
MD5: ea1c3ebcde340a4f2ea99bea353757ad
SHA1: 0c390115d39ecb28607b5276a0cb15e46384d9f6
SHA256: C7857262E1C854174240A7DCA38EE9247F4D4582F2D3B5B8133FF9143FEB080E
File Size: 74.75 KB, 74752 bytes
MD5: aa64f564cdad46453c968cb2f17bdbdc
SHA1: 45067e86a892d0b2c7c7b60a8b53aaf08195e0fd
SHA256: 8603561C0D0BDEA13ABF7966C46D57E732007D380B3960226C0B698750485A49
File Size: 353.79 KB, 353792 bytes
MD5: 2504e1b0fe97c91fd785b76722e6a152
SHA1: e1e0d56e9fb4bd9b5c3008e9405f6cc4ca167ae4
SHA256: 572CC4AD97CFB2E4019FD53279DAD6911EF34F342F4DF5F7D7E889A349809ED8
File Size: 137.73 KB, 137728 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • x86

Block Information

Total Blocks: 39
Potentially Malicious Blocks: 29
Whitelisted Blocks: 10
Unknown Blocks: 0

Visual Map

0 x x 0 x x x x x x x x x x x x 0 x x x x x 0 0 0 0 0 x x 0 0 x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MicroFake.A
  • ServStart.GA

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\hrl7e.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\hrla320.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\hrla40b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\hrlf0db.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\dlqliogm\appdata\local\temp\hrl7e.tmp C:\Users\Dlqliogm\AppData\Local\Temp\hrl7E.tmp:*:enabled:@shell32.dll,-1 RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list::c:\users\lhukkszm\appdata\local\temp\hrla40b.tmp C:\Users\Lhukkszm\AppData\Local\Temp\hrlA40B.tmp:*:enabled:@shell32.dll,-1 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • SetWindowsHookEx
User Data Access
  • GetUserObjectInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b75cda76995c677af2c7e75f9003c22175045a11_0000074240.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0c390115d39ecb28607b5276a0cb15e46384d9f6_0000074752.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\45067e86a892d0b2c7c7b60a8b53aaf08195e0fd_0000353792.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e1e0d56e9fb4bd9b5c3008e9405f6cc4ca167ae4_0000137728.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...