Trojan

Trojan.Heur.GZ.FoIfba3Wys (file analysis)

Malware Removal

The Trojan.Heur.GZ.FoIfba3Wys is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.GZ.FoIfba3Wys virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Heur.GZ.FoIfba3Wys?


File Info:

name: 7213C38B195DD12AEE2B.mlw
path: /opt/CAPEv2/storage/binaries/8744a58dad792c8167392500500e7d3da57e2c3c5cbebd04cdec0310d6168aed
crc32: 162AD597
md5: 7213c38b195dd12aee2b2916faf2bbb0
sha1: 7f27602644df213871baabd8cda588ea2b87494a
sha256: 8744a58dad792c8167392500500e7d3da57e2c3c5cbebd04cdec0310d6168aed
sha512: d0c27e5ee0ea698808f02f624e6d621e612853d936d778d2e87d43b908f18d6af05312bcbad582caa59a022f3c05ad80e30cfb767b9e35be6b99d9c1ad3dddcc
ssdeep: 49152:IV/uQ7EIzQ0LUGemsa2wP1jmxIwTAEjeqUOGiwUZ5ObXstkbSAAuKISqJrbAb/hF:IVHt1Ue2W1j/EjeqLGli5OAabSANLJvE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CEC5338A693E5C0FF4E8563FCCDB86659A38FB40DB85C7571A24B823DF139898B91314
sha3_384: 7e7a050c91f5aa65ffe36acc7565bba6113a807d79ddbb50de71b8dc799bb2302e236783e3956ee050dd0697f236d247
ep_bytes: 60be15804d008dbeeb8ff2ffc7878072
timestamp: 2022-07-30 03:14:36

Version Info:

0: [No Data]

Trojan.Heur.GZ.FoIfba3Wys also known as:

MicroWorld-eScanGen:Trojan.Heur.GZ.FoIfba3Wys
CylanceUnsafe
VIPREGen:Trojan.Heur.GZ.FoIfba3Wys
Cybereasonmalicious.b195dd
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Rozena.AZP
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.GZ.FoIfba3Wys
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Trojan.Heur.GZ.FoIfba3Wys
EmsisoftGen:Trojan.Heur.GZ.FoIfba3Wys (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7213c38b195dd12a
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.GZ.FoIfba3Wys
ArcabitTrojan.Heur.GZ.FoIfba3Wys
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
ALYacGen:Trojan.Heur.GZ.FoIfba3Wys
MAXmalware (ai score=83)
MalwarebytesMalware.Heuristic.1003
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rozena.AZP!tr
BitDefenderThetaAI:Packer.E580D2071D
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Heur.GZ.FoIfba3Wys?

Trojan.Heur.GZ.FoIfba3Wys removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment