Trojan

Trojan-PSW.Win32.Fareit.gvk removal guide

Malware Removal

The Trojan-PSW.Win32.Fareit.gvk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Fareit.gvk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristics of Ursnif spyware
  • CAPE detected the Ursnif malware family
  • Attempts to identify installed AV products by registry key

How to determine Trojan-PSW.Win32.Fareit.gvk?


File Info:

name: F35FC0475710EEC19AAC.mlw
path: /opt/CAPEv2/storage/binaries/b6e6ae07da590bfa62f97abb594568bb41022822783e7d401f9e249381b7247e
crc32: C2E0B83D
md5: f35fc0475710eec19aac813e894f4a1c
sha1: f4f894fd6dc4ab837a30589fa92a7ab148ae69f3
sha256: b6e6ae07da590bfa62f97abb594568bb41022822783e7d401f9e249381b7247e
sha512: 5f9f37a5611c34e84d248ec689b15f786ec50fe12dd3b0c35b0d19c36a4921510ac57e701de16a9a8fe6fbfe115f24d7839f6d94b33045a8617a8a6e8be97893
ssdeep: 6144:4g5db7HvSoXKszSg2EaJcjXpyQphmdxdcWP9Nklm+H5Na+LaUP0:4SzjTzqnQyzSrNamaUc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16284ADAEB5A11786CC6D15F94B4125FB9A580421FB7806EBD3143F8F68E4E1C8D38EB1
sha3_384: 01c782175ec5f9cc99dc2a563b68b1b35430e0282e0434555edaad37b6087f3d913eef522e0acd12427943970456f759
ep_bytes: 558bec6aff685851440068d032440064
timestamp: 2008-01-07 03:07:11

Version Info:

CompanyName: Live365
FileVersion: 58, 35, 14, 37
InternalName: Deflationary
LegalCopyright: Copyright © 2014
ProductName: Citizen Decustomised

Trojan-PSW.Win32.Fareit.gvk also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Papras.1552
MicroWorld-eScanTrojan.GenericKD.2867276
FireEyeGeneric.mg.f35fc0475710eec1
ALYacTrojan.GenericKD.2867276
CylanceUnsafe
ZillyaTrojan.Patched.Win32.99922
SangforTrojan.Win32.Ursnif.mt
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Fareit.476723a4
K7GWPassword-Stealer ( 004c893a1 )
K7AntiVirusPassword-Stealer ( 004c893a1 )
BitDefenderThetaGen:NN.ZexaF.34182.yu1@aqZj58gO
VirITTrojan.Win32.FileCryptor.FAT
CyrenW32/Trojan.SWMA-5962
SymantecTrojan.Zbot
ESET-NOD32Win32/Spy.Ursnif.AO
TrendMicro-HouseCallTSPY_HPDRIDEX.SM
Paloaltogeneric.ml
ClamAVWin.Malware.Agent-6367341-0
KasperskyTrojan-PSW.Win32.Fareit.gvk
BitDefenderTrojan.GenericKD.2867276
NANO-AntivirusTrojan.Win32.Yakes.efgrky
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114c6802
EmsisoftTrojan.GenericKD.2867276 (B)
ComodoMalware@#10gvlaj8ebmhn
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPDRIDEX.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosML/PE-A + Troj/Gozi-P
IkarusTrojan-Spy.Agent
JiangminTrojan.Yakes.cea
WebrootW32.Trojan.GenKD
AviraTR/Crypt.XPACK.317313
Antiy-AVLTrojan/Generic.ASMalwS.158AF3B
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanSpy:Win32/Ursnif
ViRobotTrojan.Win32.U.Agent.397729
GDataWin32.Trojan.Agent.55BHSZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C1252451
McAfeeGeneric.ys
MAXmalware (ai score=88)
VBA32TScope.Malware-Cryptor.SB
APEXMalicious
RisingSpyware.Ursnif!8.1DEF (CLOUD)
YandexTrojan.Yakes!2WZ1OMOPcsA
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EFAD!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.75710e
PandaTrj/WLT.B
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.Win32.Fareit.gvk?

Trojan-PSW.Win32.Fareit.gvk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment