Trojan

About “Trojan-PSW.Win32.Coins.ekb” infection

Malware Removal

The Trojan-PSW.Win32.Coins.ekb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Coins.ekb virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Collects information to fingerprint the system

How to determine Trojan-PSW.Win32.Coins.ekb?


File Info:

crc32: BE628CA0
md5: 811e20b87794c3dc6c5ed63980c5e145
name: 811E20B87794C3DC6C5ED63980C5E145.mlw
sha1: 34016898a718ea64bd0bc883d1a580ef64b29a09
sha256: 687e4eb6691d2f866178643d22be2e09fdf9790c3ff43fdee38d878d9b500696
sha512: cda0a69616c0e0c8d0d4dd71fb3889fc609fee86e5c2930e5e60dc722a52da896d6da007aa8c31312f03021587df4870bef71b910ce6d82e47d72417561922be
ssdeep: 12288:1x8vH2mDiH3YSiglkCa4N7/ykIRBH/YLkorriRfoyh:P62Oi5T7/ykf3i5o
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9Cloudera. All rights reserved.
InternalName: SurfsSpeechless
FileVersion: 6.7.4.7
CompanyName: Cloudera
FileDescription: Model Procedure Hopebot
LegalTrademarks: xa9Cloudera. All rights reserved.
ProductName: SurfsSpeechless
ProductVersion: 6.7.4.7
PrivateBuild: 6.7.4.7
Translation: 0x0409 0x04b0

Trojan-PSW.Win32.Coins.ekb also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Scarab.43
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.87794c
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GJFR
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-PSW.Win32.Coins.ekb
BitDefenderGen:Variant.Ransom.Scarab.43
MicroWorld-eScanGen:Variant.Ransom.Scarab.43
TencentWin32.Trojan-qqpass.Qqrob.Dwje
Ad-AwareGen:Variant.Ransom.Scarab.43
SophosMal/Generic-S
ComodoMalware@#3cf57rwld2lt2
BitDefenderThetaGen:NN.ZexaF.34688.FmKfa4AOJani
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.811e20b87794c3dc
EmsisoftGen:Variant.Ransom.Scarab.43 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Coins.ajs
AviraHEUR/AGEN.1126935
MicrosoftTrojan:Win32/Occamy.C
AegisLabTrojan.Win32.Coins.i!c
GDataGen:Variant.Ransom.Scarab.43
AhnLab-V3Malware/Win32.Generic.C2614331
McAfeeArtemis!811E20B87794
MAXmalware (ai score=95)
VBA32BScope.TrojanPSW.Azorult
PandaTrj/CI.A
RisingTrojan.Zpevdo!8.F912 (CLOUD)
YandexTrojan.PWS.Coins!oNqGVelk7K0
IkarusTrojan.PSW.Coins
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GKEA!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-PSW.Win32.Coins.ekb?

Trojan-PSW.Win32.Coins.ekb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment