Fake Trojan

How to remove “Trojan.FakeAv.NEB”?

Malware Removal

The Trojan.FakeAv.NEB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FakeAv.NEB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (22 unique times)
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Exhibits behavior characteristic of Kelihos malware
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP

How to determine Trojan.FakeAv.NEB?


File Info:

name: 5BAAE0A9979DECCFE241.mlw
path: /opt/CAPEv2/storage/binaries/c571c70d7c067294963b2bac7d2020c17b5aeacd09845f4cc1d9bbe3f93ff97d
crc32: 27752D13
md5: 5baae0a9979deccfe241665d6d59b038
sha1: 32c978396ea356cd5e114e9f28ad5a1a16458235
sha256: c571c70d7c067294963b2bac7d2020c17b5aeacd09845f4cc1d9bbe3f93ff97d
sha512: d3ea90ff440f42b1f1fe30942c26e7f95bc77177a4a65fed4f92b2f07f398691427a0a40f9d617d6785150c6fdb824940fca7df89016ea58beeae94273832aef
ssdeep: 12288:GvUSe67LsoBBuKh1c4ESVNGDxAruvCdopFfZF3RfMvNpjh1991B+2I:AFvsoBBR1c4nNCAr2O6VZPfK3jhx1B+P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184F433FB5D8C976BD42C41B1BC2B290F622EBF7A21A0022E7DD95D473EA27914601F74
sha3_384: 32454a2f8ba214bae64976359de164eda1ae14f783ac32c5e0f1f72859bf793c50fc56b68fa110d772d7a83cf4a58a8b
ep_bytes: 906a008134240230400033c9330d9a20
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.FakeAv.NEB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lmka
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.FakeAv.NEB
FireEyeGeneric.mg.5baae0a9979deccf
CAT-QuickHealTrojan.Lethic.B
McAfeeFakeAV-SecurityTool.fz
CylanceUnsafe
ZillyaTrojan.Tepfer.Win32.63325
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040797b1 )
K7GWTrojan ( 0040797b1 )
Cybereasonmalicious.9979de
VirITTrojan.Win32.FakeAV_s.OC
CyrenW32/FakeAlert.VZ.gen!Eldorado
SymantecW32.Waledac.C!gen2
ESET-NOD32a variant of Win32/Kryptik.AOBK
APEXMalicious
KasperskyTrojan-PSW.Win32.Tepfer.cggz
BitDefenderTrojan.FakeAv.NEB
NANO-AntivirusTrojan.Win32.SlymENT.bbfztm
SUPERAntiSpywareTrojan.Agent/Gen-RogueLoad
AvastWin32:FakeAV-EBI [Trj]
TencentWin32.Init.QQRob.biso
Ad-AwareTrojan.FakeAv.NEB
EmsisoftTrojan.FakeAv.NEB (B)
ComodoTrojWare.Win32.Kryptik.NEGP@4rliho
DrWebBackDoor.SlymENT.825
VIPRETrojan.Win32.Winwebsec.fd (v)
TrendMicroBKDR_KELIHOS.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.bc
SophosML/PE-A + Mal/FakeAV-OY
IkarusTrojan-PWS.Win32.Tepfer
GDataTrojan.FakeAv.NEB
JiangminTrojan/FakeAV.Gen
WebrootW32.Rogue.Gen
AviraBDS/Kelihos.foetw
Antiy-AVLTrojan[PSW]/Win32.Tepfer.cggz
ArcabitTrojan.FakeAv.NEB
ZoneAlarmTrojan-PSW.Win32.Tepfer.cggz
MicrosoftBackdoor:Win32/Kelihos.F
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R41854
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.VqW@ayDKERpc
ALYacTrojan.FakeAv.NEB
MAXmalware (ai score=81)
VBA32Malware-Cryptor.SB.01681
MalwarebytesTrojan.LameShield
TrendMicro-HouseCallBKDR_KELIHOS.SM
RisingTrojan.Win32.ZBot.cb (CLOUD)
YandexTrojan.GenAsa!KMDJJ3Ao3mI
SentinelOneStatic AI – Malicious PE
FortinetW32/FakeAlert.B!tr
AVGWin32:FakeAV-EBI [Trj]
PandaAdware/FakeAV
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.FakeAv.NEB?

Trojan.FakeAv.NEB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment