Malware

Troj/TrikBot-FK removal instruction

Malware Removal

The Troj/TrikBot-FK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/TrikBot-FK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/TrikBot-FK?


File Info:

crc32: 2EA7DAEA
md5: c5c4a0a5c1d840beb4eaadc31d3b5a3a
name: masnd.exe
sha1: 71aa6e26ab5c445fb896cb3bee4c7617e0e77d47
sha256: 3acd03733b138c0dd816d24e2cc2c3b769e94efe2618bd96173d9a855cf55a18
sha512: c0fe921a0bca943b447d4f0bbd17b227f3e2d6341a82ad2030a4f6250ce10d690b8c81f16e1059a94ae8f138cf6e79c2c88eae8cc5c91628347927b622c17bf8
ssdeep: 6144:jp/hIX7/ymDhnU/Zm3sHkkzAcWtALQ1VCgL0wH5gO0IT4qNO3ej0F9qI9u6Ziiz:jpctU/ZmWAdcQ1VPZo+3O3eg+v6ZfgY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001
InternalName: ODBCExample
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ODBCExample Application
ProductVersion: 1, 0, 0, 1
FileDescription: ODBCExample MFC Application
OriginalFilename: ODBCExample.EXE
Translation: 0x0409 0x04b0

Troj/TrikBot-FK also known as:

MicroWorld-eScanTrojan.GenericKD.33272728
FireEyeTrojan.GenericKD.33272728
Qihoo-360Win32/Trojan.095
AegisLabTrojan.Win32.Emotet.L!c
K7AntiVirusTrojan ( 005605291 )
BitDefenderTrojan.GenericKD.33272728
K7GWTrojan ( 005605291 )
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataWin32.Trojan-Spy.TrickBot.JGU5G0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
RisingTrojan.TrickBot!8.E313 (CLOUD)
Ad-AwareTrojan.GenericKD.33272728
SophosTroj/TrikBot-FK
F-SecureTrojan.TR/AD.TrickBot.snnrx
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33272728 (B)
WebrootW32.Trojan.Gen
AviraTR/AD.TrickBot.snnrx
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FBB398
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
McAfeeArtemis!C5C4A0A5C1D8
MalwarebytesTrojan.Emotet
ESET-NOD32Win32/TrickBot.CM
MAXmalware (ai score=88)
FortinetW32/Malicious_Behavior.VEX
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/TrikBot-FK?

Troj/TrikBot-FK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment