Malware

Troj/Fareit-JZH removal tips

Malware Removal

The Troj/Fareit-JZH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Fareit-JZH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Fareit-JZH?


File Info:

crc32: 85232DF9
md5: 004f65cf74786fed79027508c5ea74d8
name: vbc.exe
sha1: 765671579aac0864ceee94f0f387f5076944c18d
sha256: 5c86fcf32d1f15a745dd2f39989630ac310d1aee52af7b5f762f75f8855879ab
sha512: a6001167cd21ec382489a2263d24c1085e0a649552396ead27c82d258d1b93789578f923f43a793945b2573de478dcf357dba970606c8f3f05d30a1b64b0e365
ssdeep: 1536:1gkGTYXvIr9LcF4zlgxh1XvnV8BleY+O+Ra2TNKeDlgrBVCtw5w:mS/egFIlgzdPjRISlQVMsw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: CHONDROFIBROMA
FileVersion: 1.00
CompanyName: ubisoFT
Comments: ubisoFT
ProductName: HERPOLH
ProductVersion: 1.00
FileDescription: bddelkser
OriginalFilename: CHONDROFIBROMA.exe

Troj/Fareit-JZH also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33556334
Qihoo-360Generic/Trojan.PSW.269
McAfeeArtemis!004F65CF7478
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33556334
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_FRS.VSNW12C20
F-ProtW32/Injector.AAM.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-PSW.MSIL.Agensla.nyh
AlibabaTrojan:Win32/vbcrypt.ali2000008
AegisLabTrojan.Multi.Generic.4!c
EmsisoftTrojan.GenericKD.33556334 (B)
F-SecureTrojan.TR/Injector.pywlz
DrWebTrojan.PWS.Siggen2.45111
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.grp
FortinetW32/ELDA!tr
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.004f65cf74786fed
SophosTroj/Fareit-JZH
IkarusTrojan.VB.Crypt
CyrenW32/Injector.AAM.gen!Eldorado
AviraTR/Injector.pywlz
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D200076E
ZoneAlarmTrojan-PSW.MSIL.Agensla.nyh
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.VBKrypt.R329302
ALYacTrojan.GenericKD.33556334
Ad-AwareTrojan.GenericKD.33556334
MalwarebytesTrojan.GuLoader
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELDA
TrendMicro-HouseCallTROJ_FRS.VSNW12C20
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_82%
GDataTrojan.GenericKD.33556334
BitDefenderThetaGen:NN.ZevbaF.34100.hm0@aaeFr3hi
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Fareit-JZH?

Troj/Fareit-JZH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment