Trojan

Trojan-PSW.Win32.Fareit.ekbs removal guide

Malware Removal

The Trojan-PSW.Win32.Fareit.ekbs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Fareit.ekbs virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a registry key or value with NUL characters to avoid detection with regedit
  • Installs itself for autorun at Windows startup
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Attempts to modify browser security settings
  • Attempts to disable browser security warnings
  • Anomalous binary characteristics

How to determine Trojan-PSW.Win32.Fareit.ekbs?


File Info:

crc32: E640A2F2
md5: f256cafb1b7e226a6b80f0040b83b6c9
name: F256CAFB1B7E226A6B80F0040B83B6C9.mlw
sha1: 5748151b330545c16cee6ecef4f02570dddc02bc
sha256: 464a99ed34405e3b8d654a5acf78d2a90075f5867d5e5126a9ca97f3c9f0226b
sha512: 15f84913d9699e98e2d51003a8207b07ef40b00cb732e0b0810bd1bdeef03da4741224039b28dca9382defaf6ce6d17044606d9dfd6efe6f0f1d8f7ec1f3ff36
ssdeep: 1536:T2w8K64Klefngxy/ADC7mRg6uj+QcJUKsWjcdaEvxTW6x6mnwQFNL3eJXLOLZ:44SCYk0Puj+7uTvxHjbNiJXLOLZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 1.0.0.2
Translation: 0x0809 0x04b0

Trojan-PSW.Win32.Fareit.ekbs also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
CynetMalicious (score: 100)
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
ZillyaTrojan.Fareit.Win32.28320
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanPSW:Win32/Fareit.7626dd3b
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b1b7e2
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKXG
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-PSW.Win32.Fareit.ekbs
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.Fareit.fiahvx
ViRobotTrojan.Win32.GandCrab.170496
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentWin32.Trojan-qqpass.Qqrob.Eawk
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanSpy.Ursnif.EM@7vyz23
F-SecureHeuristic.HEUR/AGEN.1106537
BitDefenderThetaGen:NN.ZexaF.34738.hu0@a0ZBZuhG
TrendMicroTSPY_FAREIT.THOIBOAH
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
FireEyeGeneric.mg.f256cafb1b7e226a
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.nb
AviraHEUR/AGEN.1106537
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.280FF80
MicrosoftTrojan:Win32/Tiggre!rfn
AegisLabTrojan.Win32.Fareit.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.N
TACHYONTrojan-PWS/W32.Fareit.128512.BW
AhnLab-V3Trojan/Win32.Gandcrab.C2722861
Acronissuspicious
McAfeeTrojan-FQPW!F256CAFB1B7E
MAXmalware (ai score=82)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesMalware.AI.11416566
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_FAREIT.THOIBOAH
RisingTrojan.Generic@ML.100 (RDML:OihKGuDaznSGq9ZaLY58+g)
YandexTrojan.GenAsa!iewGqZUBl8A
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GKXG!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-PSW.Win32.Fareit.ekbs?

Trojan-PSW.Win32.Fareit.ekbs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment