Malware

What is “PWS:Win32/Fareit.BD!bit”?

Malware Removal

The PWS:Win32/Fareit.BD!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Fareit.BD!bit virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine PWS:Win32/Fareit.BD!bit?


File Info:

crc32: 6C698DD8
md5: a006b2950f5fd0a2dcbfc599c39ec1e6
name: A006B2950F5FD0A2DCBFC599C39EC1E6.mlw
sha1: 81bff960ddacfeee90345dc6423ec16517ba91c2
sha256: ac270162c7e066436f3f1ea77347828f8691e4ef3d747f1dfdbb7ef188ad3ab7
sha512: fa5213ec865bf7cbc011e32b14355f337d8e9a0b6d91b9aa371b9d1a117ebb414a3da7275d55480b90b26ae623e431aa0c5c71bdacf06fb62317cd975e02fde8
ssdeep: 24576:Otb20pkaCqT5TBWgNQ7aixAR/x0KoYsVQHB3F1BoyqQnQMx8P6A:7Vg5tQ7aixAR/7B3F1FQM85
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

PWS:Win32/Fareit.BD!bit also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0050a9ba1 )
Elasticmalicious (high confidence)
DrWebTrojan.AutoIt.297
CynetMalicious (score: 99)
CAT-QuickHealTrojan.AutoIt.Skeeyah.ZZ
ALYacAIT:Trojan.Nymeria.932
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0050a9ba1 )
Cybereasonmalicious.50f5fd
CyrenW32/AutoIt.QE.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.DMUI
APEXMalicious
AvastScript:SNH-gen [Trj]
ClamAVWin.Malware.Nymeria-6980382-0
KasperskyPacked.Win32.Krap.im
BitDefenderAIT:Trojan.Nymeria.932
MicroWorld-eScanAIT:Trojan.Nymeria.932
Ad-AwareAIT:Trojan.Nymeria.932
SophosMal/Generic-S
BitDefenderThetaAI:Packer.A2DA188C16
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_GEN.R005C0DFO21
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.a006b2950f5fd0a2
EmsisoftAIT:Trojan.Nymeria.932 (B)
AviraHEUR/AGEN.1100054
MicrosoftPWS:Win32/Fareit.BD!bit
GDataAIT:Trojan.Nymeria.932 (2x)
AhnLab-V3Packed/Win.Krap.C4535138
McAfeeArtemis!A006B2950F5F
MAXmalware (ai score=84)
MalwarebytesMalware.AI.3405701651
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0DFO21
IkarusTrojan.Win32.Injector
FortinetAutoIt/Krap.IM!tr
AVGScript:SNH-gen [Trj]

How to remove PWS:Win32/Fareit.BD!bit?

PWS:Win32/Fareit.BD!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment