Trojan

Trojan:MSIL/Fareit.MB!MTB malicious file

Malware Removal

The Trojan:MSIL/Fareit.MB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Fareit.MB!MTB virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan:MSIL/Fareit.MB!MTB?


File Info:

name: DC3ECB1C8E6CE6E27788.mlw
path: /opt/CAPEv2/storage/binaries/6ee567791fc31869b1f68aa60226652f3139cdd549e1e790068ea88f66296b91
crc32: B7FD379D
md5: dc3ecb1c8e6ce6e2778891077c2c208c
sha1: d60f176b3155110705f516d2b11328f2cb1b8518
sha256: 6ee567791fc31869b1f68aa60226652f3139cdd549e1e790068ea88f66296b91
sha512: 8094499c77b34541d4e5ffcbd0b7c06dde05361dd88ce0d7cc8ece9673c424dd1dd54e67e1f6a989fbc4df168bd7cdf59b4dd0b841471648dae7e9402c9178c7
ssdeep: 3072:PhA51gjol2b9d4YHhE9xTTLZ82k4NkbyLxOtyGDZTd9rusgg5J/GnUZ4SGfmcwzm:mQ6Sc654abYOoGDZTd9ruOJio4Rf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C54C2E9A1C1FFC3C1BB21305EE2762407539B59652292456FCC254F3B212EE7B85B8B
sha3_384: de9c17bc6ecdd15b7f375519eb46b47ac875ce001c9e98e13e30c557ffcb0e37dd7cdf68ba46497a4ef7d18b0d1895ca
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-28 01:24:27

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: 6665K.exe
LegalCopyright:
OriginalFilename: 6665K.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan:MSIL/Fareit.MB!MTB also known as:

LionicTrojan.MSIL.Androm.m!c
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
FireEyeGeneric.mg.dc3ecb1c8e6ce6e2
McAfeeRDN/Generic BackDoor
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3685122
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058d9f41 )
K7GWTrojan ( 0058d9f41 )
Cybereasonmalicious.c8e6ce
BitDefenderThetaGen:NN.ZemsilF.34232.sm0@a4wNryc
CyrenW32/MSIL_Troj.BUM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AEDL
TrendMicro-HouseCallTROJ_GEN.R002C0WAS22
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Androm.gen
BitDefenderGen:Heur.MSIL.Bladabindi.1
AvastWin32:Malware-gen
TencentMsil.Backdoor.Androm.Wsag
Ad-AwareGen:Heur.MSIL.Bladabindi.1
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
ComodoMalware@#pb36tc8j2qv5
DrWebTrojan.Packed2.43975
TrendMicroTROJ_GEN.R002C0WAS22
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
GDataGen:Heur.MSIL.Bladabindi.1
JiangminBackdoor.MSIL.fkqz
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftRansom.Win32.Bladabindi.sa
ArcabitTrojan.MSIL.Bladabindi.1
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
MicrosoftTrojan:MSIL/Fareit.MB!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C4922847
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=88)
MalwarebytesSpyware.LokiBot
YandexTrojan.Igent.bXnG15.9
IkarusTrojan-Spy.MSIL.Agent
FortinetMSIL/GenericKD.47819726!tr
AVGWin32:Malware-gen
PandaTrj/RnkBend.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.73691364.susgen

How to remove Trojan:MSIL/Fareit.MB!MTB?

Trojan:MSIL/Fareit.MB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment