Trojan

Should I remove “Trojan:Win32/Foidan.A”?

Malware Removal

The Trojan:Win32/Foidan.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Foidan.A virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Checks the system manufacturer, likely for anti-virtualization
  • Zeus P2P (Banking Trojan)
  • Creates a copy of itself

How to determine Trojan:Win32/Foidan.A?


File Info:

crc32: 3BBEE74E
md5: be3425974ba3b2cd2d1cca9fdbcaa65d
name: BE3425974BA3B2CD2D1CCA9FDBCAA65D.mlw
sha1: 118231f735f32e4283838b6a5519574f0c9852ef
sha256: 49d307fc3c8cc3806a056f78a57551ab8aa82f1521e17351de4d3a74f356cc50
sha512: f10eb936fdeefa890269fb7cfe5dbd52c3d57a0ed89656cf2f365c368b0417c64747872c7722e1c18c2f2b2797260574529ec0f5dab5104a09bdb886d1701541
ssdeep: 1536:SW7BhtIbRr0wANVgVuFTdF03AcZ92oJbh:S6BnIlr8VgVipMABoZh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010 Bryce Cogswell
InternalName: DiskView
FileVersion: 2.40
CompanyName: Sysinternals - www.sysinternals.com
ProductName: DiskView
ProductVersion: 2.40
FileDescription: Sysinternals Diskview
OriginalFilename: DiskView
Translation: 0x0409 0x04b0

Trojan:Win32/Foidan.A also known as:

DrWebTrojan.Inject1.37154
CynetMalicious (score: 99)
McAfeePWS-Zbot-FBBP!BE3425974BA3
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.7817
SangforTrojan.Win32.Save.a
Cybereasonmalicious.74ba3b
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.UJJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.bhuq
BitDefenderGen:Variant.Symmi.23428
NANO-AntivirusTrojan.Win32.Blocker.btefmr
MicroWorld-eScanGen:Variant.Symmi.23428
TencentWin32.Trojan.Blocker.Pgwi
Ad-AwareGen:Variant.Symmi.23428
SophosMal/Generic-S
ComodoSuspicious@#qr87i23xn7pe
BitDefenderThetaGen:NN.ZexaF.34692.dq0@aazJ2Ski
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.11FD13
McAfee-GW-EditionPWS-Zbot-FBBP!BE3425974BA3
FireEyeGeneric.mg.be3425974ba3b2cd
EmsisoftGen:Variant.Symmi.23428 (B)
WebrootW32.Malware.Gen
AviraTR/Agent.57344.43
Antiy-AVLTrojan/Generic.ASMalwS.25E156
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Foidan.A
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Symmi.23428
AhnLab-V3Trojan/Win32.Blocker.C1250539
VBA32TScope.Malware-Cryptor.SB
MAXmalware (ai score=85)
PandaTrj/Dtcontx.E
TrendMicro-HouseCallTROJ_SPNR.11FD13
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!Z+mzlGhq4AA
IkarusTrojan-Ransom.Blocker
FortinetW32/ZAccess.Y!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Foidan.A?

Trojan:Win32/Foidan.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment