Trojan

Trojan:Win32/Fareit!pz removal guide

Malware Removal

The Trojan:Win32/Fareit!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fareit!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Fareit!pz?


File Info:

name: CD1828B3C821DCE5F345.mlw
path: /opt/CAPEv2/storage/binaries/135e21089335b24bdce92ec81dd83157cecc1715304a44d0cdd24ddea40924e9
crc32: EF54C48E
md5: cd1828b3c821dce5f345095b8167884b
sha1: 25d1d376a9aaa5f8409406a9ece81000153e6a9a
sha256: 135e21089335b24bdce92ec81dd83157cecc1715304a44d0cdd24ddea40924e9
sha512: 8220bee9b2ffc467d1b4cdc9455363b25d1654dfed1abb9b6e9d93f6bd0671cd53403cc62c27a6b0f4e1155bd82f1bc4e8058239adc73333e9a3ed10843bda8e
ssdeep: 12288:A9XSdc2lUzFOlDztu9EIm4lLp013KF5NyPm:kSezFstu9E/iORKLNye
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T192D402D726CA9777FC5C0D32E9E758844AD3BD37C7A21466A9C2A32A04EA495D0FC04F
sha3_384: e021014ecf741cfc3d7c6495ef2bc2b77806edbf47650d5a96cebc9553963b92b998cc6f0cd1140dd4058845a670cec1
ep_bytes: 60bec9cebdae89c181c0281f66d16109
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Fareit!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.877447
SkyhighBehavesLike.Win32.CoinMiner.jm
McAfeeTrojan-FTRG!CD1828B3C821
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Razy.877447
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057fe481 )
AlibabaTrojan:Win32/Copak.25d8d1f7
K7GWTrojan ( 0057fe481 )
Cybereasonmalicious.6a9aaa
ArcabitTrojan.Razy.DD6387
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ECAV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Genkryptik-9839711-0
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Razy.877447
NANO-AntivirusTrojan.Win32.Copak.karxlm
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.wf
TACHYONTrojan/W32.Copak.619520.ARG
EmsisoftGen:Variant.Razy.877447 (B)
F-SecureHeuristic.HEUR/AGEN.1333454
DrWebTrojan.DownLoader42.372
ZillyaTrojan.Injector.Win32.1084019
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
JiangminTrojan.Copak.pft
VaristW32/Razy.GL.gen!Eldorado
AviraHEUR/AGEN.1333454
Antiy-AVLTrojan/Win32.Injector
Kingsoftmalware.kb.b.941
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Fareit!pz
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.877447
GoogleDetected
AhnLab-V3Win32/Viking.suspicious
BitDefenderThetaGen:NN.ZexaF.36680.LmZ@aOathWf
MAXmalware (ai score=100)
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Copak!6seu++VidZs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Fareit!pz?

Trojan:Win32/Fareit!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment