Trojan

How to remove “Trojan.Win32.Fabookie.vho”?

Malware Removal

The Trojan.Win32.Fabookie.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Fabookie.vho virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Hebrew
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Trojan.Win32.Fabookie.vho?


File Info:

name: D8B240F3092B9F56AFF2.mlw
path: /opt/CAPEv2/storage/binaries/f2f0cfbf853300bf0d5c29e04689ee0a260887db698a8b872b342df53fee02a7
crc32: 4E774FF8
md5: d8b240f3092b9f56aff2ebdd56bc187d
sha1: 3781190a864d1b1f0f826e5aa5d719eb9ffdff8e
sha256: f2f0cfbf853300bf0d5c29e04689ee0a260887db698a8b872b342df53fee02a7
sha512: df2107e045bfeee55849be4040cd84548558a92f0a53d119c57715550db15431b0d002a40626f6d1699f012573c08fc44f8c8d69c3c0b7ba395ef0b137debf34
ssdeep: 98304:s5cyhCu7aVU5X+OWkbTNiU+SAmJEwYKXrc4SxBS6sVq1XG7JGLdTmjG8nQ0:C7y4XfWkbT0UikfclxBSFVq1XGo1UnZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE6623235368110DF2D1CD3E8A2B7EF931F617369740F4B8A5EB9DC132625A09A17E93
sha3_384: 273ea9befacc18000dea6850a0dc50ecb881c714546bfcecd1bb12a319397019056040112c8694121606ff195f1abc84
ep_bytes: 6822855679e8c25af3ff663bff0fc8f9
timestamp: 2021-11-26 08:50:24

Version Info:

0: [No Data]

Trojan.Win32.Fabookie.vho also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Fabookie.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.d8b240f3092b9f56
McAfeeArtemis!D8B240F3092B
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.34062.@FW@aKkGojjO
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Fabookie.vho
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Malware-gen
McAfee-GW-EditionBehavesLike.Win32.Trojan.vc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Fabookie.qh
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Malware-gen.C4798380
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
APEXMalicious
RisingTrojan.Generic@ML.99 (RDML:IzsyB0VcouiZYgqzNc2dpg)
AVGWin32:Malware-gen

How to remove Trojan.Win32.Fabookie.vho?

Trojan.Win32.Fabookie.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment