Trojan

About “Trojan:Win32/Fareit!pz” infection

Malware Removal

The Trojan:Win32/Fareit!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fareit!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Fareit!pz?


File Info:

name: 0271B81553363F782382.mlw
path: /opt/CAPEv2/storage/binaries/81162411708201667f97aca4770999b23ba6786620f899a88116cbf27d82f0e9
crc32: E0BE5058
md5: 0271b81553363f782382e7e045a99bb6
sha1: c12f173500e48ed916f6a1a622762eabbe2b14fa
sha256: 81162411708201667f97aca4770999b23ba6786620f899a88116cbf27d82f0e9
sha512: b2a0af8e27d669e0eb53a84369144767bc5c551bb9add653e611ecab09abc08aee9e999f0cc1bc894a084a78deb08b43adc5711f15cfee0c1c8572a73576a392
ssdeep: 6144:54fvnTfNT6nJ87Ekh1tfuR9qr/N9KJuH8EG2KmQ:KfvnTNToJAtfWkNsJcG2Km
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1756413D32AC997B6FC5C0C32E9E710801AC7BC37C7A204A6A9D5A72A00E55D5D4FC69F
sha3_384: a38a9a2dac5912d272c1f19ad2d921ca42b408d2ea6c2c5ba786dfec2871cc074751c6f7f879650bb3aa2d27f897fe15
ep_bytes: 60be71a5800889f301db6129f381ee9a
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Fareit!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.smW@!RathWf
ClamAVWin.Malware.Genkryptik-9839711-0
SkyhighBehavesLike.Win32.Generic.fm
McAfeeTrojan-FTRG!0271B8155336
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Copak.Win32.66200
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057fe481 )
AlibabaTrojan:Win32/Copak.58c0e73e
K7GWTrojan ( 0057fe481 )
ArcabitTrojan.Heur.ED5B4B
BitDefenderThetaAI:Packer.0436F1211B
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.ECAV
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Trojan.Heur.smW@!RathWf
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.wf
EmsisoftGen:Trojan.Heur.smW@!RathWf (B)
F-SecureHeuristic.HEUR/AGEN.1333454
VIPREGen:Trojan.Heur.smW@!RathWf
FireEyeGeneric.mg.0271b81553363f78
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
JiangminTrojan.Copak.pft
GoogleDetected
AviraHEUR/AGEN.1333454
Antiy-AVLTrojan/Win32.Injector
Kingsoftmalware.kb.b.808
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Fareit!pz
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Trojan.Heur.smW@!RathWf
VaristW32/Razy.GL.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R435577
ALYacGen:Trojan.Heur.smW@!RathWf
MAXmalware (ai score=80)
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Injector!1.E280 (CLASSIC)
YandexTrojan.Copak!Nlgx4Nuq/sc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Fareit!pz?

Trojan:Win32/Fareit!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment