Fake

Win32:FakeAV-EEY [Trj] malicious file

Malware Removal

The Win32:FakeAV-EEY [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeAV-EEY [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:FakeAV-EEY [Trj]?


File Info:

name: B2EAD9BACF3794DB7E42.mlw
path: /opt/CAPEv2/storage/binaries/16e3563cc4637e3184be1f75121dd814e116c7310b79fa61e766ff0d3d11e694
crc32: 51AFF20C
md5: b2ead9bacf3794db7e42ceceb07b03e6
sha1: 2564b1dfb65ee3caab25eb8857b87c2f572b829e
sha256: 16e3563cc4637e3184be1f75121dd814e116c7310b79fa61e766ff0d3d11e694
sha512: d780ca06ec32b9cedf8edaa70bd91bec9a3fc211be439368af1ea3d3fb0b7230c7e379d2781deb6e8cf9a818967ae83a692bbf0ed03119319bf9e1a2ff1aeaf6
ssdeep: 12288:slXErYhjVp06SMy/ohNODpvJbvsA8/cUDr2nuKpOnAHIRWk5kuC85Qg0:GErsj7Lq2w1vaA8/c2r+MWku9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DAF4234EF3F2B5FDD00900FD8C3AEBC5B7B08047DE20991604B86A6D7A56869B714767
sha3_384: 7eb08abb883146790390ae2041d70c41bba7193b30e67f7fe6a3ede44abd2d25907b9c6dc2555171661d8aa5974e3040
ep_bytes: ff3502304000585068af2040005f8114
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Win32:FakeAV-EEY [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Lethic.B
SkyhighBehavesLike.Win32.Generic.bc
ALYacTrojan.VIZ.Gen.1
MalwarebytesTrojan.LameShield
VIPRETrojan.VIZ.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040797b1 )
K7GWTrojan ( 0040797b1 )
Cybereasonmalicious.acf379
ArcabitTrojan.VIZ.Gen.1
BaiduWin32.Trojan.Kryptik.hs
VirITTrojan.Win32.Generic.ZX
SymantecSecShieldFraud!gen10
ESET-NOD32a variant of Win32/Kryptik.APYO
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Tepfer.bjfcot
MicroWorld-eScanTrojan.VIZ.Gen.1
AvastWin32:FakeAV-EEY [Trj]
TencentWin32.Trojan.Generic.Mjgl
EmsisoftTrojan.VIZ.Gen.1 (B)
F-SecureTrojan.TR/Spy.Zbot.EB.60
DrWebTrojan.PWS.Siggen.48532
TrendMicroBKDR_KELIHOS.SM
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b2ead9bacf3794db
SophosTroj/Zbot-DDW
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Tepfer.Gen
AviraTR/Spy.Zbot.EB.60
KingsoftWin32.HeurC.KVM007.a
XcitiumTrojWare.Win32.Kryptik.SAV@4w9op4
MicrosoftBackdoor:Win32/Kelihos.F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.VIZ.Gen.1
VaristW32/Zbot.GT.gen!Eldorado
AhnLab-V3Trojan/Win32.FakeAV.R45067
McAfeeFakeAV-SecurityTool.nk
MAXmalware (ai score=88)
VBA32Trojan.FakeAV.01657
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_KELIHOS.SM
RisingSpyware.Zbot!1.9A3E (CLASSIC)
YandexTrojan.GenAsa!UiLgJYRh5Us
IkarusTrojan-PSW.Win32.Tepfer
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FakeAlert.D!tr
BitDefenderThetaGen:NN.ZexaF.36802.UqW@a4r8Mibi
AVGWin32:FakeAV-EEY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:FakeAV-EEY [Trj]?

Win32:FakeAV-EEY [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment