Malware

Troj/Fareit-JYF malicious file

Malware Removal

The Troj/Fareit-JYF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Fareit-JYF virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

How to determine Troj/Fareit-JYF?


File Info:

crc32: 8A3E72BE
md5: 75045841952fc682177c657d11fc6ad2
name: svchost.exe
sha1: 51e6890ac8244db054c6377d79c175e8595215eb
sha256: d58c6a321931008d6bea3b031312111fe6cbef1ac2baa270e8e86dc465c0fa13
sha512: f4e100e2315a1db034eaaf13fb27dbe0b4ae9ec0eab3114256358681f8792c759f43214cfe2c3836be6b2a0c2fda2162e30bc905b26478e095b959ea413c2793
ssdeep: 24576:Wtb20pkaCqT5TBWgNQ7aye/jmFyJpWge9kftGQn27M80wxdnLU+hWX6A:DVg5tQ7aye/jmFyJprlV2NxnY++5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Troj/Fareit-JYF also known as:

MicroWorld-eScanTrojan.GenericKD.42831151
FireEyeGeneric.mg.75045841952fc682
CAT-QuickHealTrojan.Zapchast.C5
McAfeeArtemis!75045841952F
SangforMalware
BitDefenderTrojan.GenericKD.42831151
K7GWTrojan ( 005621461 )
Cybereasonmalicious.ac8244
TrendMicroTROJ_FRS.VSNTC920
APEXMalicious
AvastScript:SNH-gen [Trj]
GDataWin32.Trojan-Stealer.LokiBot.P4NS51
KasperskyUDS:DangerousObject.Multi.Generic
AegisLabTrojan.Multi.Generic.4!c
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42831151 (B)
F-SecureTrojan.TR/Autoit.fjirz
DrWebTrojan.PWS.Siggen2.44597
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosTroj/Fareit-JYF
IkarusTrojan.Win32.Injector
CyrenW32/AutoIt.OM.gen!Eldorado
WebrootTrojan.Dropper.Gen
AviraTR/Autoit.fjirz
eGambitUnsafe.AI_Score_86%
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Pwsteal.Q!bit
ZoneAlarmUDS:DangerousObject.Multi.Generic
AhnLab-V3Win-Trojan/AutoInj.Exp
MalwarebytesTrojan.MalPack.AutoIt
ESET-NOD32a variant of Win32/Injector.Autoit.FDN
TrendMicro-HouseCallTROJ_FRS.VSNTC920
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.FDH!tr
Ad-AwareTrojan.GenericKD.42831151
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM10.1.C819.Malware.Gen

How to remove Troj/Fareit-JYF?

Troj/Fareit-JYF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment