Trojan

How to remove “Trojan:Win32/Fareit!pz”?

Malware Removal

The Trojan:Win32/Fareit!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fareit!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Fareit!pz?


File Info:

name: 9BAED31E590051805FF4.mlw
path: /opt/CAPEv2/storage/binaries/bf1e53a6e2e55df055703d0fc94693af07a127ca78aa40597bc5e7b0b7aab665
crc32: 3DB8C061
md5: 9baed31e590051805ff45c6bf28556ef
sha1: 81a0f0a98371759c41612c355b1422c4a6684d35
sha256: bf1e53a6e2e55df055703d0fc94693af07a127ca78aa40597bc5e7b0b7aab665
sha512: 4d5821006334350b469f56446f34bb0ce52fc27d2eba4838e9ffb7d8be8efc193598232ff1785fbdae307b8de52abfd62df3f1d12684bd0a010cb0e123683aef
ssdeep: 49152:feygphQkSFxLlPU/efaovJ1fr9H+T77sh52m9yKZ/M9Cl:mygXSFxLlPUmSovJ1xH+LQF9yKZ/M9Cl
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F08523DA77436B78CB5242B22ECA5BDBEB10C637C9194B60A11C857C35E3E3C46B61D8
sha3_384: bd1ccfff887764fe29551d73820203fe01e88659fabadce00e4227d075fe27ebd3f79ec8b23b67c02119e0db0b7cf0eb
ep_bytes: 60be148eeed6b8a5f06270f7d06181e8
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Fareit!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.414556
FireEyeGeneric.mg.9baed31e59005180
SkyhighBehavesLike.Win32.Generic.tm
McAfeeGenericRXAA-FA!9BAED31E5900
MalwarebytesTrojan.MalPack.Generic
ZillyaTrojan.Injector.Win32.1727325
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005aef1b1 )
AlibabaTrojan:Win32/Injector.227cb445
K7GWTrojan ( 005aef1b1 )
ArcabitTrojan.Lazy.D6535C
BitDefenderThetaGen:NN.ZexaF.36608.RnZ@aGXXzDe
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ECAV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Lazy-10005437-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.414556
NANO-AntivirusTrojan.Win32.Razy.kehxqu
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Tiggre.ka
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1368481
DrWebTrojan.Siggen22.17028
VIPREGen:Variant.Lazy.414556
TrendMicroTROJ_GEN.R03BC0GL123
EmsisoftGen:Variant.Lazy.414556 (B)
IkarusTrojan.Win32.Injector
VaristW32/Copak.F.gen!Eldorado
AviraHEUR/AGEN.1368481
Antiy-AVLTrojan/Win32.Injector
KingsoftWin32.HeurC.KVMH008.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Fareit!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.855VXQ
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R554362
VBA32Trojan.Copak
ALYacGen:Variant.Lazy.414556
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0GL123
RisingTrojan.Injector!1.E280 (CLASSIC)
YandexTrojan.Agent!BQaQvk4NRiY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Fareit!pz?

Trojan:Win32/Fareit!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment