Malware

Should I remove “PWS:Win32/Fareit.A”?

Malware Removal

The PWS:Win32/Fareit.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Fareit.A virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Harvests credentials from local FTP client softwares
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PWS:Win32/Fareit.A?


File Info:

name: 2CCBB6738E292A9C6B1E.mlw
path: /opt/CAPEv2/storage/binaries/f856b07308b5113ee2c89ca4ac9a5808d597bb5381d917b2826b3e26b54fa372
crc32: A185F00E
md5: 2ccbb6738e292a9c6b1e98c3d4512c56
sha1: 9a2925744c4c3d9dfd1b850772579cfe8fb84a3f
sha256: f856b07308b5113ee2c89ca4ac9a5808d597bb5381d917b2826b3e26b54fa372
sha512: db1cfe4097714d2df4d95b099389c7ce10677d2daf52060cf95df907b626bf5f8f98cfbafdd0339518a1e93f8409a24f64189974a0c2e46ddcd4866be42ec598
ssdeep: 6144:W9Yc+FSh9sOJpAE4l4JzwvXbjgYGwkuKCNdyPCkpw/q9N/SZLNwoo5cIELZDFXPO:WyEzzpAEi4JzwvHvNNdyPCkpwq9N/cLg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1766423BF7CE70AE0F53B867D3E318AA3B434B5E46F923469255A6403723C89B54798C1
sha3_384: c4b76f02488ae6f8dd2d2bb3de47538d15be0c9cde62be4407e27de0000dfed1ba293829aff655a2c4f3e515a4211c3d
ep_bytes: 60be009048008dbe0080f7ffc7879c50
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

PWS:Win32/Fareit.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Delf.kZt7
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.StealerA.7F11FC7A
SkyhighBehavesLike.Win32.Generic.fc
ALYacGeneric.StealerA.7F11FC7A
MalwarebytesMalware.AI.3782845265
VIPREGeneric.StealerA.7F11FC7A
SangforInfostealer.Win32.Fareit.Vhol
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGeneric.StealerA.7F11FC7A
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.44c4c3
ArcabitGeneric.StealerA.7F11FC7A
VirITTrojan.Win32.Delf.GMV
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/PSW.Delf.NQS
APEXMalicious
ClamAVWin.Trojan.Agent-721299
KasperskyTrojan-PSW.Win32.Tepfer.ky
AlibabaTrojanPSW:Win32/Tepfer.d7da3549
NANO-AntivirusTrojan.Win32.Tepfer.dmjgwu
ViRobotTrojan.Win32.A.PSW-Tepfer.334848[UPX]
RisingMalware.Fareit!8.E9B4 (TFE:5:5fAsGVk6xUH)
SophosMal/Generic-S
F-SecureTrojan.TR/Fareit.A
DrWebTrojan.PWS.Ftpharv.21
ZillyaTrojan.Delf.Win32.39662
TrendMicroTSPY_FAREIT.CPH15C7
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2ccbb6738e292a9c
EmsisoftGeneric.StealerA.7F11FC7A (B)
IkarusTrojan.Win32.FakeAV
MAXmalware (ai score=99)
JiangminTrojan/Generic.qspg
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Fareit.A
Antiy-AVLTrojan/Win32.Unknown
XcitiumMalware@#2dxpgrrbj5fsf
MicrosoftPWS:Win32/Fareit.A
ZoneAlarmTrojan-PSW.Win32.Tepfer.ky
GDataGeneric.StealerA.7F11FC7A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C135607
McAfeeArtemis!2CCBB6738E29
DeepInstinctMALICIOUS
VBA32BScope.TrojanPSW.Ftpharv
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTSPY_FAREIT.CPH15C7
TencentMalware.Win32.Gencirc.11b80c37
YandexTrojan.GenAsa!z7dMg064i5w
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.3499211.susgen
FortinetW32/Delf.FFWOROQ!tr.pws
BitDefenderThetaGen:NN.ZelphiF.36792.umHfaOdTboo
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove PWS:Win32/Fareit.A?

PWS:Win32/Fareit.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment