Trojan

How to remove “Trojan:Win32/Fareit.VK!MTB”?

Malware Removal

The Trojan:Win32/Fareit.VK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fareit.VK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Fareit.VK!MTB?


File Info:

crc32: BF2F8531
md5: bb81ceb407f6c0bdb4617ee83d26aced
name: BB81CEB407F6C0BDB4617EE83D26ACED.mlw
sha1: 7f8d331a86982034a5cbe3fc85eba2b18b241c39
sha256: a6ff1a7730402c48da598831ccdbc0a4910ca16ccac497e6ee86defa168e8b15
sha512: cc0d8e30fc2a767cafc65c7b649fb1747f59886ef6fa3ba86de48f7ceaad52d8b57a9b6118ca59f08813610da26a1d732cb0e51d053c054dad7d1bbb032df746
ssdeep: 6144:tujd9elX+pqqvXAb+KkCxr00VqWHAG2cNR3F1b:tYeR+R4b+KkgZgwz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: DD
InternalName: Skdefrakke0
FileVersion: 1.00
CompanyName: cisco
LegalTrademarks: DD
Comments: DD
ProductName: DD
ProductVersion: 1.00
FileDescription: DD
OriginalFilename: Skdefrakke0.exe

Trojan:Win32/Fareit.VK!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.23680
MicroWorld-eScanGen:Heur.PonyStealer.wm1@dinj7inb
FireEyeGeneric.mg.bb81ceb407f6c0bd
CAT-QuickHealTrojan.Ponystealer
Qihoo-360Trojan.Generic
McAfeeFareit-FMP!BB81CEB407F6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Androm.4!c
SangforMalware
K7AntiVirusTrojan ( 00538c151 )
BitDefenderGen:Heur.PonyStealer.wm1@dinj7inb
K7GWTrojan ( 00538c151 )
Cybereasonmalicious.407f6c
BitDefenderThetaGen:NN.ZevbaF.34804.wm1@ainj7inb
SymantecInfostealer.Lokibot
ESET-NOD32a variant of Win32/Injector.DZRH
TrendMicro-HouseCallTrojan.Win32.BAMAPANO.SM3.hp
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Androm.qdwo
AlibabaBackdoor:Win32/Androm.43f52c36
NANO-AntivirusTrojan.Win32.Androm.fhugfu
Ad-AwareGen:Heur.PonyStealer.wm1@dinj7inb
SophosMal/Generic-S + Mal/FareitVB-L
ComodoMalware@#13uu8gps0yivp
ZillyaTrojan.GenericKD.Win32.131241
TrendMicroTrojan.Win32.BAMAPANO.SM3.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
EmsisoftGen:Heur.PonyStealer.wm1@dinj7inb (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.acwc
Antiy-AVLTrojan[Backdoor]/Win32.Androm
KingsoftWin32.Troj.Agent.uu.(kcloud)
MicrosoftTrojan:Win32/Fareit.VK!MTB
ArcabitTrojan.PonyStealer.EFF1E4
ZoneAlarmBackdoor.Win32.Androm.qdwo
GDataGen:Heur.PonyStealer.wm1@dinj7inb
AhnLab-V3Win-Trojan/VBKrypt.RP08.X1976
VBA32Backdoor.Androm
ALYacGen:Heur.PonyStealer.wm1@dinj7inb
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
APEXMalicious
RisingTrojan.Kryptik!1.B4DB (CLASSIC)
YandexTrojan.GenAsa!bDmtgXeOLLw
IkarusTrojan.Win32.Injector
FortinetW32/GenKryptik.CJGS!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Trojan:Win32/Fareit.VK!MTB?

Trojan:Win32/Fareit.VK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment