Trojan

How to remove “Trojan:Win32/Sfuzuan!pz”?

Malware Removal

The Trojan:Win32/Sfuzuan!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sfuzuan!pz virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan:Win32/Sfuzuan!pz?


File Info:

name: E5122FAB112971F0CB6A.mlw
path: /opt/CAPEv2/storage/binaries/94b88bf52e83a0621f5d5ffff1b92e61ef43e62d7070a13141a5280d6d34c691
crc32: A030E6B5
md5: e5122fab112971f0cb6a6cc4be16ba7e
sha1: debd6aeaa1aae528b785e7411e22cf80604bd87e
sha256: 94b88bf52e83a0621f5d5ffff1b92e61ef43e62d7070a13141a5280d6d34c691
sha512: 45e56d780eee45c8f67ff5025a27c9b005c90ae2cf4b8e161621a6277b08ac925fcf770635968cf7b2e8575ffde5bb821ae131c133a2953dfa2518b7e1038cb2
ssdeep: 6144:ZnMfIq+XLROUxHXGmUReIqzACcgHuVzOaO+tZva:ZMgZXNOUBXXFTOAz+va
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199747B02B67084B1D7660B7F4456E3754629AE38139192CBE7A0FE3ED9312D3573B28E
sha3_384: 08a43ad5238e9ffe4d709f0ffc751ea7102569bd9514d763b9207425c46a8cd25b3b1a6118a5de477da41b89b4937888
ep_bytes: e8cb220000e979feffff8bff558bec5d
timestamp: 2014-10-12 02:10:49

Version Info:

FileDescription: 应用程序
FileVersion: 14, 10, 12, 1
LegalCopyright: Copyright (C) V 2014
ProductName: 应用程序
ProductVersion: 14, 10, 12, 1
Translation: 0x0804 0x04b0

Trojan:Win32/Sfuzuan!pz also known as:

BkavW32.AIDetectMalware
DrWebWin32.HLLM.Graz
MicroWorld-eScanGen:Variant.Doina.12184
SkyhighBehavesLike.Win32.Generic.fh
McAfeeGenericRXVO-NF!E5122FAB1129
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Sfuzuan.Win32.80
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.uy1@aWBs8gej
VirITTrojan.Win32.X-Heur.FVBT
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Sfuzuan.I
APEXMalicious
KasperskyTrojan.Win32.Sfuzuan.wy
BitDefenderGen:Variant.Doina.12184
NANO-AntivirusTrojan.Win32.Graftor.dgrhla
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.13c122bb
EmsisoftGen:Variant.Doina.12184 (B)
GoogleDetected
F-SecureTrojan.TR/Sfuzuan.tzrgv
VIPREGen:Variant.Doina.12184
FireEyeGeneric.mg.e5122fab112971f0
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Sfuzuan.u
VaristW32/Trojan.RFIL-8000
AviraTR/Sfuzuan.tzrgv
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Sfuzuan.i
Kingsoftmalware.kb.a.733
MicrosoftTrojan:Win32/Sfuzuan!pz
XcitiumTrojWare.Win32.Sfuzuan.AGR@5j48ta
ArcabitTrojan.Doina.D2F98
ZoneAlarmTrojan.Win32.Sfuzuan.wy
GDataGen:Variant.Doina.12184
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.R641840
Acronissuspicious
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Sfuzuan!8.23D (TFE:5:ZQDIe07PGuJ)
IkarusTrojan.Win32.Sfuzuan
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Sfuzuan.FF!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Sfuzuan!pz?

Trojan:Win32/Sfuzuan!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment