Trojan

Trojan.Win32.Khalesi.lqfy removal guide

Malware Removal

The Trojan.Win32.Khalesi.lqfy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Khalesi.lqfy virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Authenticode signature is invalid

Related domains:

howewerware.xyz
wpad.local-net

How to determine Trojan.Win32.Khalesi.lqfy?


File Info:

name: 63D08B591471A437C09F.mlw
path: /opt/CAPEv2/storage/binaries/4311aae978227e0446e64b6426b70da7e28b52b603f367d3823449b357bf69b2
crc32: 29BAE867
md5: 63d08b591471a437c09fd8548356eed1
sha1: af97c39426a3757561b4f4a11fd5d12333db7447
sha256: 4311aae978227e0446e64b6426b70da7e28b52b603f367d3823449b357bf69b2
sha512: d053f7cf9325895d0b7e9063421cf9c7de2eb5099c2b181fc90df70d19f3907aa47b4c764b93f3fe0c0a5e9a2863e201dff64cfb4ca525e62da1df8b7b3e64b3
ssdeep: 6144:K/NrNjEPylgTOAUMul0T+RWq0DCl4ngBz5iGjh1fXoRrNSzWyfLtQkVixFQW7iMk:y2PylgTtwRj9lwoz5iGjh1fXoqWyT2kP
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D7748DE2FF8180F1E6CA01B8A1F79B3B5D364629632495D7D3D45DB088252F0B63A39D
sha3_384: fdad1cc8feb0433b3df5148fa0a556fb62d0f25b387bd37df18ca331cf0b95cb53c80095c9a21e3590122b83229b25d5
ep_bytes: e8fb040000e974feffffc3e98baa0300
timestamp: 2021-11-15 15:01:27

Version Info:

0: [No Data]

Trojan.Win32.Khalesi.lqfy also known as:

LionicTrojan.Win32.Khalesi.4!c
MicroWorld-eScanTrojan.GenericKD.38073013
FireEyeGeneric.mg.63d08b591471a437
ALYacTrojan.GenericKD.38073013
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Khalesi.41999958
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H07KK21
Paloaltogeneric.ml
KasperskyTrojan.Win32.Khalesi.lqfy
BitDefenderTrojan.GenericKD.38073013
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.38073013
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Injector.fh
EmsisoftTrojan.GenericKD.38073013 (B)
GDataTrojan.GenericKD.38073013
AviraTR/Khalesi.plyaf
ArcabitTrojan.Generic.D244F2B5
ViRobotTrojan.Win32.Z.Khalesi.368128
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!63D08B591471
MAXmalware (ai score=81)
VBA32BScope.Trojan.Khalesi
APEXMalicious
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Trojan.Win32.Khalesi.lqfy?

Trojan.Win32.Khalesi.lqfy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment