Backdoor

What is “Backdoor:Win32/Kelihos.F”?

Malware Removal

The Backdoor:Win32/Kelihos.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Kelihos.F virus can do?

  • Attempts to connect to a dead IP:Port (11 unique times)
  • Starts servers listening on 127.0.0.1:0
  • Exhibits behavior characteristic of Kelihos malware
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP

How to determine Backdoor:Win32/Kelihos.F?


File Info:

crc32: 7036B38E
md5: 91f25b52d9bf833b9ac36e7258e44807
name: dumped.exe
sha1: a1b9024eb52a4450ae587dfddfcae37581daa5e3
sha256: 89c2d370bfa36f1d4c3e4f2ff36f966bafef3e1179319e3a4a0f2a344896bc41
sha512: 98012197368842734c9c32c650ee660051bbf179b18627dcf74a2252db553ba1ff4d1e8ffa9d0e7cd98b2b097c9cd9c7294d78026dfb11142b842386d98f4aad
ssdeep: 49152:U/stUum3+udknu1nXsNcrTrus02tsVTelDTzOw5:A8U1+uduu1n8GrTru4ni
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Kelihos.F also known as:

BkavW32.SonyAgentE.Trojan
MicroWorld-eScanGen:Variant.Graftor.Elzob.273
FireEyeGeneric.mg.91f25b52d9bf833b
CAT-QuickHealBackdoor.Kelihos
McAfeeArtemis!91F25B52D9BF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004cba681 )
BitDefenderGen:Variant.Graftor.Elzob.273
K7GWTrojan ( 004cba681 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_FRS.0NA103CE19
F-ProtW32/Kelihos.B
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Graftor.Elzob.273
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kelihos.2ca77014
NANO-AntivirusTrojan.Win32.Slym.eupess
ViRobotTrojan.Win32.Z.Kelihos.1965568
AegisLabTrojan.Win32.Generic.4!c
RisingBackdoor.Win32.Kelihos.b (CLOUD)
Ad-AwareGen:Variant.Graftor.Elzob.273
EmsisoftGen:Variant.Graftor.Elzob.273 (B)
ComodoMalware@#qlgdpkgk1j1k
F-SecureHeuristic.HEUR/AGEN.1019904
DrWebBackDoor.Slym.798
ZillyaTrojan.Kelihos.Win32.125
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.SpyAgent.th
MaxSecureTrojan.Malware.7164915.susgen
Trapminemalicious.high.ml.score
SophosTroj/Agent-AZLS
IkarusBackdoor.Win32.Kelihos
CyrenW32/Kelihos.CSIK-6531
JiangminTrojan/Generic.ancgi
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1019904
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.Elzob.273
SUPERAntiSpywareTrojan.Agent/Gen-Ursu
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Kelihos.F
AhnLab-V3Backdoor/Win32.Kelihos.R12744
Acronissuspicious
VBA32BScope.Backdoor.Slym
ALYacGen:Variant.Graftor.Elzob.23162
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kelihos.B
TrendMicro-HouseCallTROJ_FRS.0NA103CE19
TencentWin32.Backdoor.Kelihos.Hupe
YandexTrojan.Kelihos!KNWY8yM+p8E
SentinelOneDFI – Suspicious PE
eGambitGeneric.Backdoor
FortinetW32/Kelihos.JI!tr
BitDefenderThetaGen:NN.ZexaF.34090.3vW@aCPDW2f
AVGWin32:Malware-gen
Cybereasonmalicious.2d9bf8
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.c3d

How to remove Backdoor:Win32/Kelihos.F?

Backdoor:Win32/Kelihos.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment