Malware

PWS:Win32/Fareit.Q (file analysis)

Malware Removal

The PWS:Win32/Fareit.Q is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Fareit.Q virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine PWS:Win32/Fareit.Q?


File Info:

crc32: 443A448B
md5: 61cc5b5459816020b6e8c245db278dec
name: 61CC5B5459816020B6E8C245DB278DEC.mlw
sha1: 348139f3d21eabe51d65dcd516b3c7e26d121767
sha256: 5c1035e97d3760efedcfaf2e1669f98b5497036a35d8a696c65ee21703e459c5
sha512: 8eb8480769f3287288d3a13f96d12ff5e1a74ba34aa612cea7b18a1808579cf077741ef16fad53a7fa6c819345ca9e8329f9e0239f6466a3711d49405a74d80e
ssdeep: 768:9TL0x7pxaWrDBhAdfp+TLcteRoUwPZGIbjz5yu6B7VEoI5EDhcL6/E:axV1sdM3AeiHowAu+7VEocEY6E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Fareit.Q also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.UFR.2334
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.9129
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.4589
SangforTrojan.Win32.Obfuscator.ADX
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanPSW:Win32/Fareit.27185566
Cybereasonmalicious.459816
CyrenW32/Gimemo.D.gen!Eldorado
ESET-NOD32Win32/PSW.Fareit.A
APEXMalicious
AvastWin32:Reveton-LG [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.9129
NANO-AntivirusTrojan.Win32.UFR.bhmxic
ViRobotTrojan.Win32.A.Gimemo.64371
MicroWorld-eScanGen:Variant.Symmi.9129
TencentMalware.Win32.Gencirc.114d4fca
Ad-AwareGen:Variant.Symmi.9129
SophosML/PE-A
ComodoMalware@#27u6ill71s5s7
BitDefenderThetaGen:NN.ZexaF.34628.dqZ@aKBhBYbc
VIPREBackdoor.Win32.Tofsee.fa (v)
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionPWS-Zbot-FAJI!61CC5B545981
FireEyeGeneric.mg.61cc5b5459816020
EmsisoftGen:Variant.Symmi.9129 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.arhix
WebrootW32.Rogue.Gen
AviraTR/Crypt.XPACK.Gen7
eGambitGeneric.Malware
MicrosoftPWS:Win32/Fareit.Q
ArcabitTrojan.Symmi.D23A9
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Symmi.9129
AhnLab-V3Trojan/Win32.Gimemo.R49601
McAfeePWS-Zbot-FAJI!61CC5B545981
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.UFR
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
RisingStealer.Fareit!8.170 (CLOUD)
YandexTrojan.GenAsa!DSFFHssnziQ
IkarusTrojan-Ransom.Gimemo
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.AREG!tr
AVGWin32:Reveton-LG [Trj]
Qihoo-360Win32/Ransom.Reveton.HwIAEpsA

How to remove PWS:Win32/Fareit.Q?

PWS:Win32/Fareit.Q removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment