Trojan

Trojan.Win32.Fabookie.aar removal guide

Malware Removal

The Trojan.Win32.Fabookie.aar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Fabookie.aar virus can do?

  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the DLInjector04 malware family

How to determine Trojan.Win32.Fabookie.aar?


File Info:

name: E89E49ED0122E04A1A15.mlw
path: /opt/CAPEv2/storage/binaries/7a48f80fc0eddd74ceb178efcbabf90b291756868061f7d380695934b16a6116
crc32: EE87416D
md5: e89e49ed0122e04a1a15f8f6121ec467
sha1: 4874bf6931e64bd580433982ed98420851d074bd
sha256: 7a48f80fc0eddd74ceb178efcbabf90b291756868061f7d380695934b16a6116
sha512: 24cbd580f38cc3b71ae377da7a3ee2baee4d9bdd434c1739a908862fa81872cbcb7a5f2d5a5eb05ac02a79bb384f6a097fb452c3d0026b874d34b4636966c486
ssdeep: 196608:xSLUCgw99ULnNoz+mHes4zudsTJLepS+11jqbAY7Ylg:xSdgw9yDm1Hes4ydPSO1WbdWg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1746633127FF0C4B7D6820CBA4F98633177AD83224A72865B7394825F4F55EF6C1236A5
sha3_384: 105e2d258771494e321d2dc1517474af0c9f7b6cb2312d4b30ec76ccd8ab08d9b372d223bbeb45a4ce0862342da0d791
ep_bytes: 558bec6aff6898c24100680691410064
timestamp: 2019-02-21 16:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 19.00
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 19.00
Translation: 0x0409 0x04b0

Trojan.Win32.Fabookie.aar also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Stealer.l!c
DrWebTrojan.Siggen15.32500
MicroWorld-eScanGen:Variant.Jaik.45703
FireEyeGen:Variant.Jaik.45703
CAT-QuickHealTrojan.SabsikIH.S21959152
ALYacGen:Variant.Jaik.45703
CylanceUnsafe
SangforSpyware.Win32.Stealer.accp
K7AntiVirusTrojan ( 0058270d1 )
AlibabaTrojanDownloader:Win32/Fabookie.34330140
K7GWTrojan ( 0058270d1 )
Cybereasonmalicious.d0122e
BitDefenderThetaGen:NN.ZedlaF.34294.n88baOE@FOp
CyrenW32/ArkeiStealer.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
TrendMicro-HouseCallRansom_StopCrypt.R002C0DIU21
Paloaltogeneric.ml
ClamAVWin.Packed.Barys-9859531-0
KasperskyTrojan.Win32.Fabookie.aar
BitDefenderGen:Variant.Jaik.45703
NANO-AntivirusTrojan.Win32.Cryprar.jcnece
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Kryptik!1.D9CF (CLASSIC)
Ad-AwareGen:Variant.Jaik.45703
EmsisoftGen:Variant.Jaik.45703 (B)
TrendMicroRansom_StopCrypt.R002C0DIU21
McAfee-GW-EditionBehavesLike.Win32.AdwareDealPly.vc
SophosMal/Generic-R
GDataGen:Variant.Jaik.45703
JiangminTrojan.Injuke.lpe
AviraTR/Agent.xkyfc
Antiy-AVLTrojan/Generic.ASMalwS.34A6969
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Jaik.DB287
MicrosoftRansom:Win32/StopCrypt.MJK!MTB
CynetMalicious (score: 100)
McAfeeArtemis!E89E49ED0122
MAXmalware (ai score=82)
VBA32Trojan.Convagent
MalwarebytesTrojan.Dropper.SFX.Generic
TencentWin32.Trojan.Multiple.Also
MaxSecureTrojan.Malware.12570143.susgen
FortinetW32/BSE.4Q7Q!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Fabookie.aar?

Trojan.Win32.Fabookie.aar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment