Trojan

Trojan.Win32.Khalesi.pef removal instruction

Malware Removal

The Trojan.Win32.Khalesi.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Khalesi.pef virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Khalesi.pef?


File Info:

name: 479B97D26D4E3EFB4457.mlw
path: /opt/CAPEv2/storage/binaries/8f8da9c8c9b9ee2deb1b3b5dcb23a5d1b49dd417f88f5ff6ce5620aa5b79f1c4
crc32: 8D9A7040
md5: 479b97d26d4e3efb445776a9da7ef578
sha1: 1e318501a95fdf90aa0f64de4b2c0be4b07fc4ae
sha256: 8f8da9c8c9b9ee2deb1b3b5dcb23a5d1b49dd417f88f5ff6ce5620aa5b79f1c4
sha512: c397853329524af873432b5360cc20816f18a1e460f24bed34fca33986c6b3028f66473dc2d29c7f1b65796d1de49dbd888f17eeacd9a7d594c84b678f7b30f4
ssdeep: 12288:VfgJM2QgAIX1nnH7Wj9sYfwpTJIOZT2mj53qj7Qh1QRsxRIje4jSZj4F7sXgt7WF:VoJM8hb2fCIOZTPj5iQh1QRsxRIje4j8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DEF4C02FF78D0372438212B1660B95C2FF2A8579236A95A0749C809D1BB3F7D53BB2D5
sha3_384: 88e9548e2f9ff4bc945c9a4ec8e382d36b1c91bd4699042f52ad771b8df74563977f4405f229f7a4acf54b039c5dfa4e
ep_bytes: 83ec04c70424000000005b5721c24229
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Khalesi.pef also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
FireEyeGeneric.mg.479b97d26d4e3efb
SkyhighBehavesLike.Win32.Generic.bc
McAfeeGlupteba-FTTQ!479B97D26D4E
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058e60a1 )
K7GWTrojan ( 0058e60a1 )
Cybereasonmalicious.1a95fd
BitDefenderThetaGen:NN.ZexaF.36792.UyZ@aKUkY
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTKQ
APEXMalicious
ClamAVWin.Packed.Lazy-10001745-0
KasperskyHEUR:Trojan.Win32.Khalesi.pef
RisingTrojan.Kryptik!1.D284 (CLASSIC)
SophosML/PE-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen
ZillyaTrojan.Kryptik.Win32.3416494
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Khalesi.J.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Khalesi.pef
CynetMalicious (score: 100)
VBA32BScope.Trojan.Wacatac
DeepInstinctMALICIOUS
Cylanceunsafe
TencentTrojan.Win32.Kryptik.fh
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.T!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Khalesi.pef?

Trojan.Win32.Khalesi.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment