Trojan

Should I remove “Dropped:Trojan.Agent.FSOA”?

Malware Removal

The Dropped:Trojan.Agent.FSOA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Agent.FSOA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the OnlyLogger malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments

How to determine Dropped:Trojan.Agent.FSOA?


File Info:

name: D564B8B1087F7FDCDB4C.mlw
path: /opt/CAPEv2/storage/binaries/aa40900144fa80e5d2a3a42b45e885977ee33ee472659340023b336cf9c6d000
crc32: D9E2C1C2
md5: d564b8b1087f7fdcdb4c360d83f218f9
sha1: c925f11e04952548cd30f7e95afbc65bdbc86a6c
sha256: aa40900144fa80e5d2a3a42b45e885977ee33ee472659340023b336cf9c6d000
sha512: 8520e3f4646748bd7e7e6d20445715f6514679c61bf0a2c4ad7b308e365895d4ea3e7ae457c7074b93bcdd62714a693ec4cd4670c3e5a28696bb131c62f788f4
ssdeep: 98304:JqDFgJCxRNgAb/8oJ3q3NtZoiCQpWgGPTjYvsUN8MAntoML25oMR8KukTPYuix8t:JnAX9b/8iwtjTWLPTj2jmS5oVk7Yu0WL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195563313EEEBC1FBE8374430E97C99890BB6457A3B447DDA56392A113C423F5988960F
sha3_384: 13fd924994d56eb0d1c074234864c4babb7cab5fd8b0f7abf2a93e729a331375bbefce76cc73190eaf4dcd7741b39189
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2020-08-01 02:44:18

Version Info:

0: [No Data]

Dropped:Trojan.Agent.FSOA also known as:

LionicTrojan.Win32.Agent.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.Agent.FSOA
FireEyeGeneric.mg.d564b8b1087f7fdc
CAT-QuickHealBackdoor.Manuscrypt
ALYacDropped:Trojan.Agent.FSOA
CylanceUnsafe
AlibabaTrojan:Win32/DelfInject.ali2000015
BitDefenderThetaGen:NN.ZexaF.34182.xq0@aeEeo2bj
CyrenW32/Trojan.BXQD-4583
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Dropper.Pswtool-9857487-0
KasperskyBackdoor.Win32.Agent.myugrq
BitDefenderDropped:Trojan.Agent.FSOA
NANO-AntivirusRiskware.Win32.PSWTool.hqsnsl
AvastWin32:Malware-gen
TencentWin32.Backdoor.Agent.Wqmm
SophosTroj/Krypt-FV
ComodoMalware@#3excwn0owlbku
DrWebTrojan.Inject4.24892
McAfee-GW-EditionBehavesLike.Win32.HToolPassView.vc
EmsisoftDropped:Trojan.Agent.FSOA (B)
GDataDropped:Trojan.Agent.FSOA
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1144141
Antiy-AVLTrojan[Backdoor]/Win32.Agent
KingsoftWin32.PSWTroj.Undef.(kcloud)
ArcabitTrojan.Agent.FSOA
ZoneAlarmBackdoor.Win32.Agent.myugrq
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!D564B8B1087F
MAXmalware (ai score=84)
VBA32Backdoor.Manuscrypt
MalwarebytesMalware.AI.1689158496
TrendMicro-HouseCallTROJ_GEN.R002C0WAN22
RisingDropper.Agent/NSIS!1.D805 (CLASSIC:bWQ1OkWZfb+L1oejp5U8V8IG5qw)
IkarusTrojan-Downloader.Win32.Agent
FortinetRiskware/Application
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Dropped:Trojan.Agent.FSOA?

Dropped:Trojan.Agent.FSOA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment