Malware

About “Troj/Fareit-JTQ” infection

Malware Removal

The Troj/Fareit-JTQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Fareit-JTQ virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine Troj/Fareit-JTQ?


File Info:

crc32: 9273F491
md5: 22f07b8d4eb07dcd62e06f1e3466088a
name: tttttt.exe
sha1: 25153c2de643b99d5c8731314fd4e41f78f7b9e4
sha256: 9e62d13e28c82ed0d1a0f3e234d841b90ec7f4ec7feb6ab8b4912f19af8eea98
sha512: 557c4425421ba4ec2650280e383391ea43ee289fb3dd09b16d1482de585c820e1a80263e63dcf4de66a38c5f56f156eeda0878547850d458428b1805ee858b2a
ssdeep: 6144:dpvSlyKZuwUejFp0ROQIYVGK9g855nE5s:dwlyKZq0X0ROQnaSnE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2013
InternalName: EMailSpliter
FileVersion: 1, 0, 0, 1
CompanyName: by suruiqiang (Y!M: suruiqiang)
ProductName: EMailSpliter
ProductVersion: 1, 0, 0, 1
FileDescription: EMailSpliter
OriginalFilename: EMailSpliter.EXE
Translation: 0x0804 0x04b0

Troj/Fareit-JTQ also known as:

MicroWorld-eScanTrojan.GenericKD.33371856
FireEyeGeneric.mg.22f07b8d4eb07dcd
McAfeePacked-FWY!22F07B8D4EB0
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056081c1 )
BitDefenderTrojan.GenericKD.33371856
K7GWTrojan ( 0056081c1 )
CrowdStrikewin/malicious_confidence_60% (W)
Invinceaheuristic
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:KeyloggerX-gen [Trj]
GDataTrojan.GenericKD.33371856
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaBackdoor:MSIL/GenKryptik.d0fa4a65
NANO-AntivirusTrojan.Win32.Androm.hccvve
AegisLabTrojan.MSIL.Androm.m!c
RisingBackdoor.Androm!8.113 (CLOUD)
Ad-AwareTrojan.GenericKD.33371856
EmsisoftTrojan.Crypt (A)
ComodoMalware@#3bbz7az66tfv6
F-SecureTrojan.TR/Kryptik.oojsb
DrWebTrojan.DownLoader33.7086
TrendMicroTROJ_GEN.R03FC0PBQ20
McAfee-GW-EditionPacked-FWY!22F07B8D4EB0
Trapminemalicious.moderate.ml.score
SophosTroj/Fareit-JTQ
IkarusTrojan.MSIL.Inject
CyrenW32/MSIL_Kryptik.AHD.gen!Eldorado
AviraTR/Kryptik.oojsb
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FD36D0
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
MicrosoftTrojan:Win32/Pwsteal.Q!rfn
AhnLab-V3Trojan/Win32.Agent.R284273
Acronissuspicious
ALYacTrojan.GenericKD.33371856
MAXmalware (ai score=85)
MalwarebytesSpyware.LokiBot
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/GenKryptik.EFBM
TrendMicro-HouseCallTROJ_GEN.R03FC0PBQ20
TencentWin32.Trojan.Agent.Auto
FortinetMSIL/Kryptik.UQP!tr
BitDefenderThetaGen:NN.ZemsilF.34090.Hm0@aW5TAmBj
AVGWin32:KeyloggerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM03.0.9089.Malware.Gen

How to remove Troj/Fareit-JTQ?

Troj/Fareit-JTQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment