Trojan

What is “Trojan.Foreign.Gen.2”?

Malware Removal

The Trojan.Foreign.Gen.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Foreign.Gen.2 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan.Foreign.Gen.2?


File Info:

crc32: EEC4C09B
md5: da3181b8dce6c043c738b862ac035abd
name: DA3181B8DCE6C043C738B862AC035ABD.mlw
sha1: 200ec01d0cade809201480fcd9d041dc84137457
sha256: ae56fa5176747994b8b1d62df07cdc3e3b0d5e4ea849887679b0f909f9b145a9
sha512: e899840834e3de1bb32e1ae01b44ad4446629ac8b4c455f7eff849bb2034502974abfa6736d679fa36b2bf32793bda6d70f6118d737ee01fffae3a602dd6b1bf
ssdeep: 6144:NF4wuz1u1t3tfwYuHb5EB88SZBYmP3pXp7uSNP3qEDNCoLeK2ZHWbUuAg:NF7SE1t3tf0Hb5OSb/PvRzQoLUWbUuAg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2004-2014. All rights reserved.
InternalName: HWMonitorPro.exe
FileVersion: 1.1.9.0
CompanyName: CPUID
ProductName: Hardware Monitor PRO
ProductVersion: 1.1.9.0
FileDescription: Hardware Monitor PRO
OriginalFilename: HWMonitorPro.exe
Translation: 0x0419 0x04b0

Trojan.Foreign.Gen.2 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00420ee01 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.22973
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot.A5
ALYacTrojan.Foreign.Gen.2
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.21884
SangforRansom.Win32.Foreign_45.se
CrowdStrikewin/malicious_confidence_100% (D)
K7GWSpyware ( 004b9d251 )
Cybereasonmalicious.8dce6c
CyrenW32/A-d2ae482e!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/Spy.Zbot.ABA
ZonerTrojan.Win32.26293
APEXMalicious
AvastWin32:Dropper-gen [Drp]
ClamAVWin.Trojan.Blocker-386
KasperskyTrojan-Ransom.Win32.Blocker.foep
BitDefenderTrojan.Foreign.Gen.2
NANO-AntivirusTrojan.Win32.TrjGen.deprsw
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
MicroWorld-eScanTrojan.Foreign.Gen.2
TencentTrojan-ransom.Win32.Blocker.foep
Ad-AwareTrojan.Foreign.Gen.2
SophosML/PE-A + Troj/Zbot-IWI
ComodoTrojWare.Win32.Spy.Zbot.APON@5fup4g
BitDefenderThetaGen:NN.ZexaF.34678.yq0@a4jXkHbk
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTSPY_ZBOT.SM30
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.da3181b8dce6c043
EmsisoftTrojan.Foreign.Gen.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.qld
AviraTR/Spy.Zbot.twyew
eGambitUnsafe.AI_Score_99%
MicrosoftTrojanDownloader:Win32/Recslurp.B
ArcabitTrojan.Foreign.Gen.2
GDataTrojan.Foreign.Gen.2
TACHYONTrojan/W32.Blocker.408576.AD
AhnLab-V3Trojan/Win32.Necurs.R118620
Acronissuspicious
McAfeeGeneric-FAVU!DA3181B8DCE6
MAXmalware (ai score=86)
VBA32Hoax.Blocker
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SM30
RisingDownloader.Recslurp!8.9C8 (RDMK:cmRtazrReEZr/tE7Tl8Lam2ka8Dj)
YandexTrojan.Blocker!V3qUpiab2lw
IkarusTrojan.Win32.Spy
FortinetW32/Kryptik.CKTI!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.1.B566.Malware.Gen

How to remove Trojan.Foreign.Gen.2?

Trojan.Foreign.Gen.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment