Trojan

Trojan:Win32/Foosace!dha removal instruction

Malware Removal

The Trojan:Win32/Foosace!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Foosace!dha virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Foosace!dha?


File Info:

name: B2DC7C29CBF8D71D1DD5.mlw
path: /opt/CAPEv2/storage/binaries/c6a9db52a3855d980a7f383dbe2fb70300a12b7a3a4f0a995e2ebdef769eaaca
crc32: 46D565C0
md5: b2dc7c29cbf8d71d1dd57b474f1e04b9
sha1: c637e01f50f5fbd2160b191f6371c5de2ac56de4
sha256: c6a9db52a3855d980a7f383dbe2fb70300a12b7a3a4f0a995e2ebdef769eaaca
sha512: cf60db89f91c744f33af6654d14c20e3d6bf961eeb337fba2a538136a683f48bf47108e05be0e0abcb9abe9ce6764b88a164edfc94885c1b8d4b0b6b34adb489
ssdeep: 49152:GMBfyWXTTvcnJtY8eSz7HZh4kpqBup/WWlAEQEnLO:GMF36CG74kp33
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172A56C22AF810536D8965D7AF5FA923AFAF17590835DC5C36AD074B034172E0AD3F2CA
sha3_384: ddb2ba4a5bc3586488aad76cbf41b00eb654227e9126d2f9584adc933415e2eb2aaca71e8282746b961e9a86fefa0b55
ep_bytes: 558bece888b80000e8030000005dc3cc
timestamp: 2015-07-02 09:42:44

Version Info:

0: [No Data]

Trojan:Win32/Foosace!dha also known as:

BkavW32.Common.A0F45089
LionicTrojan.Win32.Foosace.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Zusy.1944
FireEyeGeneric.mg.b2dc7c29cbf8d71d
SkyhighTrojan-FQOY!B2DC7C29CBF8
McAfeeTrojan-FQOY!B2DC7C29CBF8
Cylanceunsafe
ZillyaTrojan.Agent.Win32.1619615
SangforTrojan.Win32.Foosace.Vygw
K7AntiVirusTrojan ( 0055e3dd1 )
AlibabaTrojan:Win32/Foosace.9485f85a
K7GWTrojan ( 0055e3dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.90EDD42121
VirITTrojan.Win32.Generic.FVU
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.RKP
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Zusy.1944
NANO-AntivirusTrojan.Win32.Agent.dxbmag
AvastWin32:Malware-gen
TencentWin32.Trojan.Agen.Azlw
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1319481
DrWebBackDoor.Reverse.216
VIPREGen:Variant.Ser.Zusy.1944
TrendMicroTrojan.Win32.FOOSACE.AA
EmsisoftGen:Variant.Ser.Zusy.1944 (B)
IkarusTrojan.Win32.Agent
GDataGen:Variant.Ser.Zusy.1944
JiangminTrojan.Generic.mwsy
GoogleDetected
AviraHEUR/AGEN.1319481
Antiy-AVLTrojan/Win32.Apt28
XcitiumMalware@#1wzo2eg0wejt7
ArcabitTrojan.Ser.Zusy.D798
ZoneAlarmUDS:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Foosace!dha
AhnLab-V3Trojan/Win32.Agent.C2370687
VBA32BScope.Trojan.Dynamer
ALYacGen:Variant.Ser.Zusy.1944
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.FOOSACE.AA
RisingBackdoor.[APT28]XTunnel!1.A367 (CLASSIC)
YandexTrojan.GenAsa!8nuDhBHwR/A
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.RKP!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Foosace!dha?

Trojan:Win32/Foosace!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment