Trojan

About “Trojan-PSW.Win32.Fareit.dzri” infection

Malware Removal

The Trojan-PSW.Win32.Fareit.dzri is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Fareit.dzri virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
myp0nysite.ru

How to determine Trojan-PSW.Win32.Fareit.dzri?


File Info:

crc32: A5A0CD49
md5: 902520746cfc798190cbaf6534753dac
name: 902520746CFC798190CBAF6534753DAC.mlw
sha1: 44c5238e6e4a0398815cc55ce71a6ef15ccd8f4c
sha256: 3baa3afdc0dbd4cc6bd1db808eae12356bfe7bb8e4640d96116a38111367a5fd
sha512: e1c1413414b0836272e3b75d9ecdf2f80d4c1539e2bcfed6ce8d1518a54cbd3c01a57b5d348cca115f98b11fb8b06f188c88b9572496cf3d629fa7ce79f2800a
ssdeep: 12288:7R5/w3xXEe81ImSy86o+zVSb/XeYjlgY5fU:bm/6Ayw+JSb/uYSI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: GJSe 'computiNG FORceo'
InternalName: Selflocking2
FileVersion: 8.07
LegalTrademarks: ePSON
Comments: HEA Ve TOop soft war
ProductName: tie kOSSA
ProductVersion: 8.07
OriginalFilename: Selflocking2.exe

Trojan-PSW.Win32.Fareit.dzri also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052f9e21 )
LionicTrojan.Win32.Fareit.i!c
Elasticmalicious (high confidence)
DrWebTrojan.VbCryptENT.1665
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.Nm0@daY7Zini
CylanceUnsafe
ZillyaTrojan.Fareit.Win32.26154
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Fareit.b5f38ae2
K7GWTrojan ( 0052f9e21 )
Cybereasonmalicious.46cfc7
CyrenW32/Kryptik.ATC.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.DXTP
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Fareit-6782540-1
KasperskyTrojan-PSW.Win32.Fareit.dzri
BitDefenderGen:Heur.PonyStealer.Nm0@daY7Zini
NANO-AntivirusTrojan.Win32.Fareit.fbgujc
MicroWorld-eScanGen:Heur.PonyStealer.Nm0@daY7Zini
TencentWin32.Trojan-qqpass.Qqrob.Hphl
Ad-AwareGen:Heur.PonyStealer.Nm0@daY7Zini
SophosMal/Generic-R + Mal/FareitVB-L
ComodoMalware@#tvwghc4e663h
BitDefenderThetaGen:NN.ZevbaF.34050.Nm0@aaY7Zini
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_FAREIT.THEODAH
McAfee-GW-EditionBehavesLike.Win32.Fareit.jh
FireEyeGeneric.mg.902520746cfc7981
EmsisoftGen:Heur.PonyStealer.Nm0@daY7Zini (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117871
Antiy-AVLTrojan/Generic.ASMalwS.25FBE7B
MicrosoftVirTool:Win32/VBInject.AHV!bit
GDataGen:Heur.PonyStealer.Nm0@daY7Zini
TACHYONTrojan-PWS/W32.Fareit.647168
AhnLab-V3Win-Trojan/VBKrypt.RP12.X2026
Acronissuspicious
McAfeeFareit-FLP!902520746CFC
MAXmalware (ai score=98)
VBA32TrojanPSW.Fareit
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_FAREIT.THEODAH
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.PWS.Fareit!yC/5jvjAIJs
IkarusTrojan.Win32.Injector
FortinetW32/GenKryptik.CFIF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.PonyRAT.HwMAEpsA

How to remove Trojan-PSW.Win32.Fareit.dzri?

Trojan-PSW.Win32.Fareit.dzri removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment