Fake

About “Win32:FakeAV-EHG [Trj]” infection

Malware Removal

The Win32:FakeAV-EHG [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:FakeAV-EHG [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (22 unique times)
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Exhibits behavior characteristic of Kelihos malware
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics

How to determine Win32:FakeAV-EHG [Trj]?


File Info:

name: BF48D67187A7F05235CB.mlw
path: /opt/CAPEv2/storage/binaries/b1f2708e351a26b0e0a1470d56f36a57f6deeb263d8e2aef4c563de0ee22edcd
crc32: 34B27C89
md5: bf48d67187a7f05235cbe1eea0ea0a9c
sha1: 0235fbfd44030652e3ca811d7f9522b0ed6f5c69
sha256: b1f2708e351a26b0e0a1470d56f36a57f6deeb263d8e2aef4c563de0ee22edcd
sha512: 2285694273fbfcdb4d199998a0027aacec4040b5ae20a0d76528f6b2559af2d8ee9d626680da1c77aed2e9d7e0154dd4c1d287cde3fce5976beb36a961cd8f8d
ssdeep: 12288:it17WmQ36YeQAj8a5eV+g2YyemOxlMVG5MGYeN+3le3IMCOiDAnuW5e5+:ivivKHQAj8kbO66MGfQ1kMB6uW5eA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133F4334C4C4181B8CB11E6B06B09CE796E237CC1F998A71C36E0FB8D54F6B95D876AD2
sha3_384: 2c13538fdcbc5d36e50523b6d689d5900b0ce0d616e49bc2a1db6798005f9bebc3f83f8ab451eb897008c4ae09e42a36
ep_bytes: 68004040005f8d35d02f40006a1d59f3
timestamp: 2012-08-31 23:11:12

Version Info:

0: [No Data]

Win32:FakeAV-EHG [Trj] also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.bf48d67187a7f052
CAT-QuickHealTrojan.Lethic.B
McAfeeBackDoor-FJW
MalwarebytesMalware.AI.2508706408
ZillyaTrojan.Kryptik.Win32.995887
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.187a7f
BitDefenderThetaGen:NN.ZexaF.34212.UqW@aGAsjlk
CyrenW32/FakeAlert.WP.gen!Eldorado
SymantecW32.Waledac.D!gen1
ESET-NOD32a variant of Win32/Kryptik.ARUZ
BaiduWin32.Trojan.Kryptik.ur
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Tepfer.bgeiwc
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
AvastWin32:FakeAV-EHG [Trj]
TencentWin32.Init.QQRob.culk
Ad-AwareTrojan.VIZ.Gen.1
EmsisoftTrojan.VIZ.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.ARLI@4t2kfq
DrWebBackDoor.Slym.1375
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroWORM_KELIHOS.SMB
McAfee-GW-EditionBehavesLike.Win32.VirRansom.bc
SophosML/PE-A + Troj/Zbot-DKJ
GDataTrojan.VIZ.Gen.1
JiangminTrojan/Tepfer.Gen
AviraTR/Winwebsec.AJ.76
Antiy-AVLTrojan/Generic.ASMalwS.129576F
KingsoftWin32.Heur.KVM004.a.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Kelihos.F
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R48344
Acronissuspicious
VBA32Trojan.FakeAV.01657
MAXmalware (ai score=86)
TrendMicro-HouseCallWORM_KELIHOS.SMB
RisingTrojan.Bulta!8.35D (CLOUD)
YandexTrojan.GenAsa!EQdKRqlhQiI
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.X!tr
AVGWin32:FakeAV-EHG [Trj]
PandaTrj/Tepfer.B
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:FakeAV-EHG [Trj]?

Win32:FakeAV-EHG [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment