Malware

PWS:Win32/Fareit.AQ!MTB removal tips

Malware Removal

The PWS:Win32/Fareit.AQ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Fareit.AQ!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine PWS:Win32/Fareit.AQ!MTB?


File Info:

crc32: D3EC2B67
md5: 24051a0cc0d70f8afbcc6cd16869959d
name: ahihix.exe
sha1: c1c04618dbad328b0d508a0410eedd32be171475
sha256: d81c957e19d3914c062506af166d34bad9b22756fa08f50a0061c43999e5683e
sha512: 0fa507100d5fc563862ca98f010485481d63eba15b3670493979ce783997f136898cd9890f77d90e98f748ccb491b63761203c568d6182341618cec7e81e4acb
ssdeep: 24576:0kAVCi74LofeHXecQmiDXeOcWtMXFlnNBfx:0iiuo2Oq4XeOcUKXnnZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Fareit.AQ!MTB also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Zusy.308908
FireEyeGeneric.mg.24051a0cc0d70f8a
Qihoo-360HEUR/QVM05.1.7152.Malware.Gen
McAfeeFareit-FVZ!24051A0CC0D7
BitDefenderGen:Variant.Zusy.308908
Cybereasonmalicious.cc0d70
TrendMicroTSPY_HPLOKI.SMBD
APEXMalicious
GDataGen:Variant.Zusy.308908
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Injector!8.C4 (TFE:dGZlOgXgJPzH1gh73A)
Invinceaheuristic
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.308908 (B)
SentinelOneDFI – Malicious PE
ArcabitTrojan.Zusy.D4B6AC
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftPWS:Win32/Fareit.AQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Suspicious/Win.Delphiless.X2085
ALYacGen:Variant.Strictor.246974
MAXmalware (ai score=82)
Ad-AwareGen:Variant.Zusy.308908
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EMOY
TrendMicro-HouseCallTSPY_HPLOKI.SMBD
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.EMOG!tr
BitDefenderThetaAI:Packer.67948BC121

How to remove PWS:Win32/Fareit.AQ!MTB?

PWS:Win32/Fareit.AQ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment