Malware

Win32/Kelihos.C (file analysis)

Malware Removal

The Win32/Kelihos.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kelihos.C virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (14 unique times)
  • Starts servers listening on 127.0.0.1:0
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits behavior characteristic of Kelihos malware
  • Installs itself for autorun at Windows startup
  • Installs WinPCAP

How to determine Win32/Kelihos.C?


File Info:

crc32: 48506F64
md5: 16e855e5642ee6b21ccdfef286a5e505
name: 16E855E5642EE6B21CCDFEF286A5E505.mlw
sha1: 5b12cca3602c2119c08b37e10f987d4ae56f959e
sha256: eae15b3182b402e687336f242ab658f73590c3c882843a84eaea409cd387c0fc
sha512: 1eb9310e879b20494737d8fcd841fee3596ea70c5d570849598ee5ccf256f3cf1464e04318440b3ace871b69a26004e626f7ba713d464d7269333d53ab63f0a7
ssdeep: 24576:yuYcvy4Y9kDHYmm1rzMWVex5sCmQbN4hBAr/oeOPAQ5Q9Ts:yMhmN3MOyb2mDobPBQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2010
InternalName: UIScanner
FileVersion: 13,0,21,1
CompanyName: BitDefender S.R.L.
ProductName: BitDefender 2010
ProductVersion: 13,0,18,344
FileDescription: BitDefender Antivirus Scanner
OriginalFilename: uiscan.exe
Translation: 0x0409 0x04b0

Win32/Kelihos.C also known as:

K7AntiVirusTrojan ( 0026c9311 )
DrWebBackDoor.Slym.16
CynetMalicious (score: 100)
ALYacGen:Heur.FKP.1
CylanceUnsafe
ZillyaBackdoor.Bredolab.Win32.5251
AlibabaTrojan:Win32/Obfuscator.f08b26e1
K7GWTrojan ( 0026c9311 )
Cybereasonmalicious.5642ee
CyrenW32/S-bdcee22a!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kelihos.C
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.FKP.1
NANO-AntivirusTrojan.Win32.Bredolab.daggt
MicroWorld-eScanGen:Heur.FKP.1
TencentWin32.Trojan.Generic.Eanw
Ad-AwareGen:Heur.FKP.1
SophosML/PE-A + Mal/FakeAV-MR
ComodoMalCrypt.Indus!@1qrzi1
BitDefenderThetaGen:NN.ZexaF.34692.9mKfaWw8Yrii
VIPRETrojan.Win32.Ransom.do (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.16e855e5642ee6b2
EmsisoftGen:Heur.FKP.1 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.183998D
MicrosoftTrojan:Win32/Occamy.C
AegisLabTrojan.Win32.Bredolab.m!c
GDataGen:Heur.FKP.1
AhnLab-V3Trojan/Win32.FakeAV.R5556
McAfeeFakeAV-SecurityTool.jq
MAXmalware (ai score=100)
VBA32Trojan.ExpProc.014
MalwarebytesTrojan.FakeAV
PandaTrj/CI.A
RisingTrojan.Win32.Generic.128CE4F4 (C64:YzY0Otg25BIxOtnW)
IkarusTrojan.Win32.Yakes
FortinetW32/BrowHost.KP!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Win32/Kelihos.C?

Win32/Kelihos.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment