Fake

SFX:FakeJPG-A [Trj] removal guide

Malware Removal

The SFX:FakeJPG-A [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SFX:FakeJPG-A [Trj] virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine SFX:FakeJPG-A [Trj]?


File Info:

name: 9450A75C52B628CBBCF8.mlw
path: /opt/CAPEv2/storage/binaries/0f907d566c7c67322d5b29310776017b18784fc557b54608c9c863f6c83d1f3c
crc32: 673577C4
md5: 9450a75c52b628cbbcf8a8dd4a88741f
sha1: b768988a6d305ca4e92f953941a25d440dbc4dca
sha256: 0f907d566c7c67322d5b29310776017b18784fc557b54608c9c863f6c83d1f3c
sha512: a858ffa4d75014ef24646cdbcd623edb1d6e5d146a0b5265760b8374a4377d0f93f23b9059cb9db111fa4a560c5d0219f3380b03745311e30c66f55b31a45e00
ssdeep: 24576:1DWHSb4NJYUH1fb1MWqo9FNoMyHKSliccR:884oUVT1M4tZyqS4ccR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185051202FD8254B2C6711D365936BB21693D7A200F248BDFA3D04A6EA9711D1B731FEB
sha3_384: 8ee5f9e1a70fcb096ff40e959def37e101ae52830cc1b44b562d0d2075da4071395df4eef440531f576b6c192201df63
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

SFX:FakeJPG-A [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.NanoBot.trQD
MicroWorld-eScanTrojan.GenericKDZ.88166
FireEyeGeneric.mg.9450a75c52b628cb
ALYacTrojan.GenericKDZ.88166
MalwarebytesRozena.Trojan.Shell.DDS
VIPRETrojan.GenericKDZ.88166
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win64/Goshell.89e4e46d
K7GWTrojan ( 00561a0d1 )
Cybereasonmalicious.a6d305
CyrenW64/Rozena.CF.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/Rozena.CL
APEXMalicious
KasperskyUDS:Trojan.Win64.Goshell.gen
BitDefenderTrojan.GenericKDZ.88166
AvastSFX:FakeJPG-A [Trj]
TencentWin64.Trojan.Goshell.Edhl
EmsisoftTrojan.GenericKDZ.88166 (B)
F-SecureHeuristic.HEUR/AGEN.1318206
DrWebBackDoor.Meterpreter.157
TrendMicroBackdoor.Win32.COBEACON.YXDESZ
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosMal/Generic-S
GDataTrojan.GenericKDZ.88166
AviraHEUR/AGEN.1318206
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win64.Rozena
ArcabitTrojan.Generic.D15866
ViRobotTrojan.Win.Z.Rozena.796269
ZoneAlarmUDS:Trojan.Win64.Goshell.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C4201634
Acronissuspicious
McAfeeArtemis!9450A75C52B6
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallBackdoor.Win32.COBEACON.YXDESZ
IkarusTrojan.WinGo.Rozena
MaxSecureTrojan.Malware.300983.susgen
FortinetW64/Rozena.AQ!tr
AVGSFX:FakeJPG-A [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove SFX:FakeJPG-A [Trj]?

SFX:FakeJPG-A [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment