Fake

Troj/FakeAV-EKL removal tips

Malware Removal

The Troj/FakeAV-EKL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/FakeAV-EKL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Troj/FakeAV-EKL?


File Info:

name: 2D1FBED235A45DF8E2EA.mlw
path: /opt/CAPEv2/storage/binaries/239b4d810d44fb6881465ca2914c97cfa15a09fd3fd02c14299e5babe9f7f2c1
crc32: 867AFC6E
md5: 2d1fbed235a45df8e2ea84e6dfe23e96
sha1: da07cea65365047ed491e6a2fcacf561f5c5f5f8
sha256: 239b4d810d44fb6881465ca2914c97cfa15a09fd3fd02c14299e5babe9f7f2c1
sha512: f8bc3a11a6635653606f693069dc4b49b4664d08fed47884759f20deecf7927ec380ba065e5c8c57a069e96155e98da95960984d692056ec952500560bd8d3da
ssdeep: 1536:xIZZpp48Zd0lo+4EMMyO3OexOSEowTwBjzvcmJoxDWqfqNII2Ca2B:aZSlI/HUOjSiToj7CEqfqg2B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17BA3F2A5A8C1E177C040C1B201B49B175F37292F0762A65B87882D8F7F3D6446B7E34B
sha3_384: 66bc8f8e16879e55bb18601a54ccdefe54577f564da6219cf9d5ecd965905f3daf19a93d6268125b6d6703e005aa5fc7
ep_bytes: 6a606828614000e8db0e0000bf940000
timestamp: 2011-02-05 10:05:06

Version Info:

0: [No Data]

Troj/FakeAV-EKL also known as:

BkavW32.HomyqEnpunD.Trojan
LionicTrojan.Win32.Crypt.tnoY
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
CAT-QuickHealTrojan.Ramnit.A5
SkyhighBehavesLike.Win32.VirRansom.nc
ALYacTrojan.Ransom.Cerber.1
Cylanceunsafe
VIPRETrojan.Ransom.Cerber.1
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003c36381 )
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 003c36381 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36792.gqX@aWcKC1oi
VirITWorm.Win32.Agent.AEA
SymantecW32.Ramnit.B!gen2
ESET-NOD32a variant of Win32/Kryptik.KLV
APEXMalicious
ClamAVWin.Trojan.Agent-1344700
KasperskyTrojan.Win32.Crypt.cvw
AlibabaTrojan:Win32/Kryptik.8d6eaf95
NANO-AntivirusTrojan.Win32.Autoruner1.favlcg
ViRobotTrojan.Win32.A.Menti.99840.Z
RisingMalware.XPACK!1.64E1 (CLASSIC)
SophosTroj/FakeAV-EKL
BaiduWin32.Trojan.Kryptik.at
F-SecureMalware.W32/Sality.DQ
DrWebWin32.HLLW.Autoruner1.39240
ZillyaTrojan.Crypt.Win32.15168
TrendMicroTSPY_ZBOT.SMHA
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2d1fbed235a45df8
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=100)
JiangminTrojan/Menti.ooe
WebrootW32.Ramnit.Gen
GoogleDetected
AviraW32/Sality.DQ
VaristW32/Trojan.LSEZ-6430
Antiy-AVLTrojan[Backdoor]/Win32.Azbreg.pyv
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Ramnit
XcitiumTrojWare.Win32.Agent.PIN@4kr97j
ArcabitTrojan.Ransom.Cerber.1
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmTrojan.Win32.Crypt.cvw
GDataWin32.Trojan.PSE.7F8R4F
CynetMalicious (score: 100)
McAfeePWS-Zbot.gen.ass
TACHYONTrojan/W32.Lebag.99840
DeepInstinctMALICIOUS
VBA32Trojan.Crypt
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Ramnit.F
ZonerTrojan.Win32.Ramnit.31976
TrendMicro-HouseCallTSPY_ZBOT.SMHA
TencentTrojan.Win32.Fednu.uaz
YandexTrojan.Ramnit!cLbJ7UZPdfE
IkarusVirus.Win32.Vundo
MaxSecureBackdoor.Azbreg.pyv
FortinetW32/Kryptik.KLV!tr
AVGWin32:Agent-APCY [Trj]
Cybereasonmalicious.653650
AvastWin32:Agent-APCY [Trj]

How to remove Troj/FakeAV-EKL?

Troj/FakeAV-EKL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment