Fake

Win32:FakeAV-EFD [Trj] (file analysis)

Malware Removal

The Win32:FakeAV-EFD [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeAV-EFD [Trj] virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:18871, :0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates Zeus (Banking Trojan) mutexes
  • Zeus P2P (Banking Trojan)
  • Generates some ICMP traffic
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32:FakeAV-EFD [Trj]?


File Info:

crc32: 2B6D7B45
md5: 66f09be44e2703826968dc41bc84944b
name: 66F09BE44E2703826968DC41BC84944B.mlw
sha1: 04fa35ad8725882c0446fa51d79c5a4938890e62
sha256: b6d021ae861c7179f1a168de8d554ec538b9e1eb309a3ece127181dfa49f185a
sha512: b0e43e468c69954f1ce1e626142fa6dfe482a93497036ef70850604cadd6f06549cb514809bf619c7fd6a0c4de8dbf850da7130c9c6a7b742ef5e69e65455624
ssdeep: 6144:vOV+NXDq+wCoV+/vf/8+eKFPltpxnNJzYrMXYRHY+T0+4p38O:vOVIDlM+/v3wcltrj8dRg+iM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32:FakeAV-EFD [Trj] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040797b1 )
LionicTrojan.Win32.Generic.lmka
Elasticmalicious (high confidence)
DrWebTrojan.Packed.24465
MicroWorld-eScanTrojan.VIZ.Gen.1
CAT-QuickHealTrojan.Lethic.B
ALYacTrojan.VIZ.Gen.1
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.94088
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Winwebsec.61dfeb3c
K7GWTrojan ( 0040797b1 )
Cybereasonmalicious.44e270
BaiduWin32.Trojan.Kryptik.hs
CyrenW32/Zbot.GT.gen!Eldorado
SymantecW32.Waledac.C!gen2
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
AvastWin32:FakeAV-EFD [Trj]
ClamAVWin.Dropper.Zeus-9800470-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Packed.crdcwg
TencentWin32.Trojan.Generic.Wrqm
Ad-AwareTrojan.VIZ.Gen.1
SophosMal/Generic-R + Mal/EncPk-AJO
ComodoTrojWare.Win32.Kryptik.AQDB@4t36vp
BitDefenderThetaGen:NN.ZexaF.34266.tqW@aOVQzsfc
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroTROJ_KRYPTIK.SMP
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.66f09be44e270382
EmsisoftTrojan.VIZ.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Tepfer.Gen
WebrootW32.Trojan.VIZ.Gen
AviraTR/Winwebsec.ooiuwo
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.49636A
KingsoftWin32.Heur.KVMH004.a.(kcloud)
MicrosoftPWS:Win32/Zbot!GO
ArcabitTrojan.VIZ.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-RogueAV
GDataTrojan.VIZ.Gen.1
AhnLab-V3Trojan/Win32.Tepfer.R45480
Acronissuspicious
McAfeePWS-Zbot.gen.arv
MAXmalware (ai score=100)
VBA32Trojan.FakeAV.01657
MalwarebytesTrojan.LameShield
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTIK.SMP
RisingTrojan.Generic@ML.100 (RDML:AVqTqeRTWy05DCatxj9YaA)
YandexTrojan.GenAsa!RXE4rsW6Gdo
IkarusTrojan-PSW.Win32.Tepfer
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.ATCI!tr
AVGWin32:FakeAV-EFD [Trj]
Paloaltogeneric.ml

How to remove Win32:FakeAV-EFD [Trj]?

Win32:FakeAV-EFD [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment