Trojan

About “Trojan:Win32/Fareit.RF!MTB” infection

Malware Removal

The Trojan:Win32/Fareit.RF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fareit.RF!MTB virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Fareit.RF!MTB?


File Info:

crc32: BD00C160
md5: 0228fb66019eda727dd89ff9ed08495f
name: 0228FB66019EDA727DD89FF9ED08495F.mlw
sha1: 19b5b485900a51a23e7c708100809ef161a84dd2
sha256: 65fde50589aeecb442c71375f93907321b221ca9390b96058d9d738cd2c3a66d
sha512: 2043d5849796875e8dbf4ac2956585f8b5bea2665090c0cb8067c4c94554ca9e79e3504d5d41a07d7eedd984d81060e42b32f759b3721a71dd24cb724e314a15
ssdeep: 24576:CX2aUAKvTWIBwUo49MYa4HvjBT5q/XQBoG:CX5tsddGG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Fareit.RF!MTB also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.63178
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37130474
SangforBackdoor.Win32.Remcos.gen
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Remcos.3c11377f
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5900a5
CyrenW32/Trojan.BKRL-2848
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPOJ
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderTrojan.GenericKD.37130474
MicroWorld-eScanTrojan.GenericKD.37130474
Ad-AwareTrojan.GenericKD.37130474
ComodoTrojWare.Win32.Agent.cwgob@0
TrendMicroTROJ_FRS.0NA104FM21
FireEyeTrojan.GenericKD.37130474
EmsisoftTrojan.GenericKD.37130474 (B)
WebrootW32.Trojan.Gen
eGambitPE.Heur.InvalidSig
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Fareit.RF!MTB
AegisLabTrojan.Win32.Remcos.m!c
GDataTrojan.GenericKD.37130474
AhnLab-V3Trojan/Win.Generic.C4531761
McAfeeRDN/RemcosRAT
MAXmalware (ai score=85)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA104FM21
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Fareit.RF!MTB?

Trojan:Win32/Fareit.RF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment