Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Redmond desk5 min

Malwarebytes flags Trojan.FakeMS.ED after Windows 11 installation: how to investigate safely

A Trojan.FakeMS.ED alert after Windows 11 setup does not prove Windows is infected—or that Malwarebytes is wrong. Use this evidence-first checklist to identify the file, verify its source and decide what to do next.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: the name Trojan.FakeMS.ED alone cannot show that Windows 11 is infected or that Malwarebytes made a mistake. It is a Malwarebytes detection family for trojans that imitate legitimate Microsoft files. Treat the item as unsafe until you identify its exact path, hash, origin and scan results.

What Trojan.FakeMS.ED tells you—and what it does not

Malwarebytes describes Trojan.FakeMS as a generic detection family for trojans that attempt to look like legitimate Microsoft files. The .ED suffix identifies a signature variant, not a complete diagnosis. It does not establish that the file is part of Windows, that the Windows installer is compromised, or that the alert is a false positive. See Malwarebytes’ detection description at Malwarebytes’ Trojan.FakeMS page.

The timing is also inconclusive. A detection appearing during or after setup may involve installation media, a temporary setup file, a copied application, a restored backup, a secondary drive, removable media or a network-protection event. “Detected after installing Windows 11” is not the same as “caused by Windows 11.”

First, preserve the evidence

Do not restore the item or add it to the Allow list while its origin is uncertain. Open Malwarebytes → Detection History, select the relevant entry and record or export:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Norton 360 Deluxe 2027 Antivirus, 5 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
  • Malwarebytes version and database version
  • Windows edition and full build number
  • Detection date and time
  • Whether it was a scan result or real-time protection event
  • Exact detection name, file name, extension and complete path
  • Action taken: quarantined, blocked or ignored
  • SHA-256 hash, if shown
  • Whether the alert recurred after reboot or an update

Quarantine places the item in an isolated location where it cannot normally run. Manage quarantined items through Detection History as described in Malwarebytes’ quarantine instructions. Isolation is not proof that the detection was correct; a false positive can be quarantined too.

Determine which situation you have

Possible false positive

A false positive becomes plausible when the file came from official Microsoft media, is expected at that path, has a valid signature, matches a trusted hash, is not flagged by reputable second opinions and disappears after a Malwarebytes database correction. Those clues are supporting evidence, not an automatic clearance.

Unofficial or altered installation media

Torrents, file-sharing sites, “optimized” images, unofficial mirrors and repackaged installers can contain modified executables. An unsigned file, invalid signature, unexpected publisher, hash mismatch or agreement among several security products is a reason to discard the media and obtain fresh installation media from Microsoft’s Windows 11 download page.

Rank #2
Sale
McAfee Total Protection 2027 Antivirus Software for 1 Device | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.

Something carried over from the old system

A clean installation does not sanitize every attached disk or restored file. Check secondary internal drives, USB devices, browser downloads, application installers, scheduled tasks, startup entries and backups copied back after setup. Disconnect external storage temporarily if the detection returns, then scan each device separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A network event rather than a file detection

Malwarebytes can report a blocked website or IP connection, sometimes with a displayed process such as System. That is investigated differently from a quarantined executable. Confirm the event type in Detection History before attributing it to Windows files. A related Malwarebytes forum discussion illustrates that update-related alerts can be network events: forum discussion.

Verify the file and installation source

Hash the file or ISO

If the file still exists, calculate its SHA-256 hash in PowerShell:

Rank #3
Webroot Internet Security Plus | Antivirus Software 2026 | 3 Device | 1 Year Keycard for PC/Mac/Chromebook/Android/IOS + Password Manager | Packaged Version
  • STAY PROTECTED EVERYWHERE you go, at home, in a café, at the airport—everywhere—on ALL YOUR DEVICES, with cloud-based protection against viruses & other online threats
  • Webroot PASSWORD MANAGER by Last Pass creates, encrypts, and saves all your passwords, so you only have to remember one.
  • As the #1 TRUSTED PROVIDER OF THREAT INTELLIGENCE, you know you’re in good hands. Stay safe from viruses, ransomware, phishing, and more.
  • Webroot SOFTWARE UPDATES ITSELF AUTOMATICALLY, so you always have the most current protection without lifting a finger—and updates happen in the background so they won’t slow you down.
  • PREMIUM FEATURES: Encrypts & protects passwords and account information for all your devices so you can stay protected wherever you are.

Get-FileHash -Algorithm SHA256 "C:pathtofile.exe"

For installation media:

Get-FileHash -Algorithm SHA256 "C:pathtoWindows11.iso"

Compare the result with a trusted value from Microsoft or the organization that supplied the media. A hash by itself proves only identity, not safety.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check a Windows executable’s signature

  1. Right-click the file and choose Properties.
  2. Open Digital Signatures.
  3. Check the signer, signature status and certificate details.

A valid Microsoft signature supports legitimacy, but it is not an absolute verdict: signed software can be abused, and some legitimate components may not present an obvious signature.

Rank #4
Sale
Norton 360 Deluxe 2027 Antivirus, 3 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.

Capture the exact Windows build

Press Win + R, enter winver, and record the complete build. You can also run:

Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber

Safe response sequence

  1. Leave the detection quarantined; do not click Restore or Allow.
  2. Export the Detection History report and save screenshots of the entry.
  3. Update Malwarebytes, then run another scan.
  4. Run a full Microsoft Defender scan. If active malware is a credible concern, use Microsoft Defender Offline from Windows Security.
  5. Stop using questionable installation media and replace it with media downloaded directly from Microsoft.
  6. Scan USB drives, secondary disks and restored backups before reconnecting or copying from them.
  7. Compare the exact file—not just detection counts—when Malwarebytes and Defender disagree.

Malwarebytes advises adding an item to its Allow list only when you are absolutely certain it is harmless. Its current control is under Detection History → Allow list; see the Allow-list guidance. Never exclude an entire Downloads folder, temporary directory, USB drive or system directory to make setup proceed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Webroot Internet Security Complete | Antivirus Software 2026 | 5 Device | 1 Year Download for PC/Mac/Chromebook/Android/IOS + Password Manager, Performance Optimizer
  • POWERFUL, LIGHTNING-FAST ANTIVIRUS: Protects your computer from viruses and malware through the cloud; Webroot scans faster, uses fewer system resources and safeguards your devices in real-time by identifying and blocking new threats
  • IDENTITY THEFT PROTECTION AND ANTI-PHISHING: Webroot protects your personal information against keyloggers, spyware, and other online threats and warns you of potential danger before you click
  • SUPPORTS ALL DEVICES: Compatible with PC, MAC, Chromebook, Mobile Smartphones and Tablets including Windows, macOS, Apple iOS and Android
  • NEW SECURITY DESIGNED FOR CHROMEBOOKS: Chromebooks are susceptible to fake applications, bad browser extensions and malicious web content; close these security gaps with extra protection specifically designed to safeguard your Chromebook
  • PASSWORD MANAGER: Secure password management from LastPass saves your passwords and encrypts all usernames, passwords, and credit card information to help protect you online
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When, if ever, should you test Malwarebytes as the cause?

Malwarebytes’ interference guidance permits temporarily quitting the application to test software known to be safe, with protection restored immediately afterward: Malwarebytes’ troubleshooting instructions. For a Windows installer, do not casually disable protection. Verify the media and file first, then reproduce the issue in a controlled environment or disposable test machine. Successful installation with Malwarebytes disabled proves only that Malwarebytes was blocking or interfering with something; it does not prove that the item was safe.

How to report a suspected false positive

Submit the Detection History log and, where safe and permitted, the sample. Include:

  • Full path, file name and SHA-256 hash
  • Malwarebytes and database versions
  • Windows edition and build
  • Installation or download source and reproduction steps
  • Detection screenshots and whether it was scan or real-time protection
  • Results from Microsoft Defender and other reputable scanners

Paid users can contact Malwarebytes Support. Other users can use the Malwarebytes forum’s false-positive process, as explained in Malwarebytes’ false-positive reporting guidance and its current support article. A researcher may request additional details before confirming or correcting a signature.

How to read the outcome

Evidence What it means
Official Microsoft file; alert vanishes after a database update Strong indication of a false positive, pending confirmation.
Unofficial source, modified media or hash mismatch Treat the media as potentially unsafe and replace it.
Unsigned or invalidly signed executable Escalate; do not allow it automatically.
Only Malwarebytes detects an official, validated file A false positive is plausible, but still requires review.
Several reputable scanners detect the same hash Evidence of a genuine threat is substantially stronger.
Detection is on a backup or external drive Windows 11 may be incidental to the infection.
Alert is a blocked connection Investigate the destination, process and network event separately.
Detection returns after quarantine Look for another copy, persistence, scheduled tasks or a second infected source.
No path, hash, log or analyst response exists The case remains unresolved; neither “infected” nor “false positive” is justified.

Bottom line

Trojan.FakeMS.ED after Windows 11 installation is an evidence-collection problem, not a verdict. Keep the item quarantined, identify exactly what was detected, verify the media and hash, scan independently and obtain Malwarebytes’ review before restoring or allowing anything. Without the original log and a confirmed file analysis, the incident cannot responsibly be labeled either a compromised Windows installer or a false positive.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.