Trojan

Should I remove “Trojan:Win32/Foosace!rfn”?

Malware Removal

The Trojan:Win32/Foosace!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Foosace!rfn virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Foosace!rfn?


File Info:

name: 77089C094C0F2C15898F.mlw
path: /opt/CAPEv2/storage/binaries/eb6620442c3ab327f3ccff1cc6d63d6ffe7729186f7e8ac1dbbbfddd971528f0
crc32: EF06F365
md5: 77089c094c0f2c15898ff0f021945148
sha1: f3d50c1f7d5f322c1a1f9a72ff122cac990881ee
sha256: eb6620442c3ab327f3ccff1cc6d63d6ffe7729186f7e8ac1dbbbfddd971528f0
sha512: 8bf4507f5df0cfe37f31e646e457ef8a147cc0d9691601ec2c7a088c3a9777fed448de0c542ae448d69ac18aee180e5a6ebe513d72d828f98eb91aafdcf77c1a
ssdeep: 6144:/0mBAD36EeM9k+vgdcz445WH3CBwuckb1GHeDQwR5swGo:/0m+D3i+vgdcQ3CS44cl5swx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115759D3423AD80B1FD6839B66722F6D6057D7A1DCAE01611A9CF34F46D2BC9433CA26D
sha3_384: 2a47473275870e733894972e4fc60f3907d1a3f7c78e1ce491bcd04b10261a7a06367ede547c6e1544ae01330bb0a19b
ep_bytes: e86f1f0000e989feffff8bff558bec81
timestamp: 2015-07-09 07:02:10

Version Info:

0: [No Data]

Trojan:Win32/Foosace!rfn also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.SednitCred.4!c
Elasticmalicious (high confidence)
DrWebTrojan.SednitCred.7
MicroWorld-eScanGen:Variant.BlackEnergy.3
FireEyeGeneric.mg.77089c094c0f2c15
CAT-QuickHealTrojan.Dynamer.27602
SkyhighBehavesLike.Win32.PUPXAS.tz
McAfeeArtemis!77089C094C0F
Cylanceunsafe
ZillyaTrojan.Agent.Win32.563369
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3dd1 )
AlibabaTrojan:Win32/Sofacy.0b2aef42
K7GWTrojan ( 0055e3dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.BlackEnergy.3
BitDefenderThetaAI:Packer.3F5707AC1F
VirITTrojan.Win32.SednitCred.H
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.XIJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.BlackEnergy.3
NANO-AntivirusTrojan.Win32.Agent.duvrgv
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Cwnw
SophosML/PE-A
F-SecureHeuristic.HEUR/AGEN.1317455
VIPREGen:Variant.BlackEnergy.3
TrendMicroTROJ_DROPPR.YYUV
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.BlackEnergy.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bizhc
GoogleDetected
AviraHEUR/AGEN.1317455
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Apt28
Kingsoftmalware.kb.a.1000
XcitiumMalware@#1zsgwe3knzym
MicrosoftTrojan:Win32/Foosace!rfn
ViRobotTrojan.Win32.S.Agent.1615360.M
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.BlackEnergy.3
AhnLab-V3Trojan/Win32.Foosace.C975360
VBA32BScope.Trojan.SednitCred
ALYacGen:Variant.BlackEnergy.3
MalwarebytesMalware.AI.3392691500
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_DROPPR.YYUV
RisingTrojan.Agent!8.B1E (TFE:5:4k95XTwspZJ)
YandexTrojan.Agent!cWVLso7JJDs
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.XIJ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.f7d5f3
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Foosace!rfn?

Trojan:Win32/Foosace!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment