Trojan

Trojan:Win32/Refeys.B information

Malware Removal

The Trojan:Win32/Refeys.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Refeys.B virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Anomalous binary characteristics

How to determine Trojan:Win32/Refeys.B?


File Info:

crc32: 30B2F4F5
md5: e6f0e94e73d0653b35221441167aa6fe
name: E6F0E94E73D0653B35221441167AA6FE.mlw
sha1: 5b2da2442ebdc0c4f763b9942377179f7c6d4b5e
sha256: 8c42af5e83a38bb90c8266e50540a767c398e299ebdea63bf4d62aa7e9750050
sha512: 288adcf49140b6a442a2d6861277c47174f08f80699d690969a9affd3f96d9b79b916214aecec85b9a92456a222db976e7746263d748e3d67bf11cca3d9dc0e7
ssdeep: 1536:PQ8azzbs4pqgu7lxFb0ggxiw4vNLVtMc15KaBGiZP/daL:PsbXqgMFb01iw45UuwW9/s
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: oplhSFdSoimnP
1: HgHCix02KlNmYT
CompanyName: Red Line Software
FileVersion: 1.4.1.4
FileDescription: WUpsemNOdrFj
Translation: 0x0409 0x0000

Trojan:Win32/Refeys.B also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebBackDoor.Chimerka.3
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.GandCrab.1212
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Generic.25859314
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e73d06
CyrenW32/Trojan.NMTU-1221
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Agent.OEI
APEXMalicious
AvastWin32:Agent-ARTQ [Trj]
KasperskyTrojan-Dropper.Win32.Sysn.awij
BitDefenderGen:Variant.Ransom.GandCrab.1212
NANO-AntivirusTrojan.Win32.Chimerka.ecrfwi
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1212
TencentWin32.Trojan-banker.Loader.Anfk
Ad-AwareGen:Variant.Ransom.GandCrab.1212
SophosMal/Generic-S
ComodoMalware@#2pn41rnq0ldqt
BitDefenderThetaGen:NN.ZexaF.34608.fC0@aOtx@Zli
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.35JA13
McAfee-GW-EditionBehavesLike.Win32.Swisyn.mh
FireEyeGeneric.mg.e6f0e94e73d0653b
EmsisoftGen:Variant.Ransom.GandCrab.1212 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1123844
eGambitUnsafe.AI_Score_65%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Refeys.B
ArcabitTrojan.Ransom.GandCrab.D4BC
GDataGen:Variant.Ransom.GandCrab.1212
Acronissuspicious
McAfeeArtemis!E6F0E94E73D0
MAXmalware (ai score=88)
VBA32BScope.Trojan-Dropper.Injector
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SPNR.35JA13
RisingSpyware.Agent!8.C6 (CLOUD)
YandexTrojan.DR.Demp!/qB1MJ2c5Pw
IkarusTrojan-Dropper.Win32.Demp
FortinetW32/Shiz.NCF!tr
AVGWin32:Agent-ARTQ [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Sysn.HxQB2GYA

How to remove Trojan:Win32/Refeys.B?

Trojan:Win32/Refeys.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment