Trojan

TrojanDownloader:Win32/Dofoil!pz removal guide

Malware Removal

The TrojanDownloader:Win32/Dofoil!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Dofoil!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Dofoil!pz?


File Info:

name: E5ACD4C2A2BA509A3411.mlw
path: /opt/CAPEv2/storage/binaries/12f4184bd4a9b47cc567df245e13aed49762910c8951af11c1101eda63a8b5fd
crc32: B4A37BF7
md5: e5acd4c2a2ba509a34113e4cbed52509
sha1: 92e3abeae0bcd8fb9ecd6e4ac552ea8f2126146a
sha256: 12f4184bd4a9b47cc567df245e13aed49762910c8951af11c1101eda63a8b5fd
sha512: 4573519888fda4ffbed2cbf698df8b20510320b66c1b70a2b78059bc3609e4323c70751ab98555fc9b813a12f83e36d96134f2a306017c4c1e89ca196be5acc7
ssdeep: 6144:ZCEF/mUcJ531nIUliViSZbLhaZfvMlLXICgc:DFQOUMBQf0ljWc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12D841927A589B1F7F4E34CB21A4F92B2A1719B302714D643B60CDB5AA7703C1E6252DF
sha3_384: 4e42b856b02e8a1c5a043b3d198ded25b65d5dbb796cccda05d6b4f4a6664cbd96071f561a8ba228282b08ac5c0935ba
ep_bytes: e88a120000e950feffffcccccccc9055
timestamp: 1993-07-29 09:59:49

Version Info:

CompanyName: Microsoft Corporation
FileDescription: PANOSE(tm) Font Mapper
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: PANMAP
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: PANMAP.DLL
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

TrojanDownloader:Win32/Dofoil!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader46.50608
MicroWorld-eScanGen:Variant.Zusy.433908
FireEyeGeneric.mg.e5acd4c2a2ba509a
CAT-QuickHealBackdoor.Hupigon.18637
SkyhighBehavesLike.Win32.Virut.fh
McAfeeGenericRXMP-SW!E5ACD4C2A2BA
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Variant.Zusy.433908
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.A96FFF4F1F
VirITTrojan.Win32.Tinba.FS
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.DGEY
APEXMalicious
ClamAVWin.Trojan.Tinba-6169133-0
KasperskyHEUR:Trojan.Win32.Tinba.pef
BitDefenderGen:Variant.Zusy.433908
NANO-AntivirusTrojan.Win32.Tinba.erausx
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Crypt-SAF [Trj]
TencentTrojan.Win32.Tinba.fa
EmsisoftGen:Variant.Zusy.433908 (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroTROJ_TINBA.SMALY
SophosMal/Vawtrak-H
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.105SOSL
JiangminTrojan.Generic.dsitt
WebrootW32.Trojan.Gen
VaristW32/Agent.BGEW-7875
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.Generic
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Tinba.BE@6ujvp3
ArcabitTrojan.Zusy.D69EF4
ZoneAlarmHEUR:Trojan.Win32.Tinba.pef
MicrosoftTrojanDownloader:Win32/Dofoil!pz
CynetMalicious (score: 100)
Acronissuspicious
ALYacGen:Variant.Zusy.433908
VBA32Malware-Cryptor.Limpopo
Cylanceunsafe
ZonerTrojan.Win32.71284
TrendMicro-HouseCallTROJ_TINBA.SMALY
RisingSpyware.Tinba!1.AE6E (CLASSIC)
YandexTrojan.GenAsa!a8Y7Wxsq32E
IkarusTrojan.Win32.Crypt
FortinetW32/Tinba.BE!tr
AVGWin32:Crypt-SAF [Trj]
Cybereasonmalicious.ae0bcd
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Dofoil!pz?

TrojanDownloader:Win32/Dofoil!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment