Malware

Mal/Fareit-AA removal tips

Malware Removal

The Mal/Fareit-AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Fareit-AA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Mal/Fareit-AA?


File Info:

crc32: 36B3234B
md5: da199c3ff9419ff77fc055a11d85a691
name: agonx.exe
sha1: 4edc17e2e6716faaa4c7628b2c97f9ce61240abb
sha256: 289ee22d7ba393c8de030be1be6a8f06d214dc327576c7d2645f0dfe564d919b
sha512: ce3f8bf8ec1397d91bc8d983ba2127956252169d6110dbc94b137b3236d4aec2fc70a8d49d8322301a5ae4e139e365596377d25f4a9d26d2d385bd851e645792
ssdeep: 12288:3CXsis9pz3g2qrfg9x74qZ8cixZsc+38QjjAIWdxzSHkv9zyBJeCqfVXVgPo:SxMz3g2q0jjixZ/+38Q3NklMJ9qNXVAo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 e Softwre Fof.org>
InternalName: gperf
FileVersion: 3.0.1.1765
License: This program is free softrib andodify it under the terms of the GNU General Public License;see www.gnu.org/copyleft/gpl.html.
CompanyName: GNgnu.org>
SpecialBuild: GNU in32
LegalTrademarks: GNUerfxae
WWW: http://wf.html
ProductName: Gperf
ProductVersion: 3.0.1.1765
FileDescription: Gperf: generatfect hash function from a key set
OriginalFilename: gperf.exe
Translation: 0x0409 0x04e4

Mal/Fareit-AA also known as:

DrWebTrojan.Nanocore.23
MicroWorld-eScanGen:Variant.Ursu.857091
FireEyeGeneric.mg.da199c3ff9419ff7
McAfeeFareit-FSK!DA199C3FF941
CylanceUnsafe
VIPRETrojan.Win32.Simda.ba (v)
SangforMalware
K7AntiVirusTrojan ( 005660d51 )
BitDefenderGen:Variant.Ursu.857091
K7GWTrojan ( 005660d51 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.34108.2G0@aeSuD9pi
APEXMalicious
GDataGen:Variant.Ursu.857091
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
Ad-AwareGen:Variant.Ursu.857091
SophosMal/Fareit-AA
F-SecureHeuristic.HEUR/AGEN.1133569
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
EmsisoftGen:Variant.Ursu.857091 (B)
AviraHEUR/AGEN.1133569
ArcabitTrojan.Ursu.DD1403
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Suspicious/Win.Delphiless.X2059
Acronissuspicious
VBA32BScope.Trojan.Crypt
ALYacGen:Variant.Ursu.857091
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.DLF.Generic
ESET-NOD32a variant of Win32/Injector.ELTL
RisingTrojan.Injector!8.C4 (TFE:5:1X4PiP7CmvG)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELTL!tr
Cybereasonmalicious.2e6716
Qihoo-360HEUR/QVM05.1.0474.Malware.Gen

How to remove Mal/Fareit-AA?

Mal/Fareit-AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment