Backdoor

Backdoor:Win32/Fynloski.A removal instruction

Malware Removal

The Backdoor:Win32/Fynloski.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Fynloski.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Fynloski.A?


File Info:

crc32: 2389AC4D
md5: 621d4055fc8ff4d6fea43e02c1cfa892
name: f9bdce8978170f6f.exe
sha1: ee49fa20ad0af2c8ea75a1e4954aa907abc91555
sha256: 302ccabd3153cbf88006b403a3380b8f4f901bda60087a7115e7e0ff4c2a9801
sha512: 39ac76ba99f8926c6fe96ad9306436805ea54f7dd499586b18d22ede1b48b28ffa94df893c281144a449492510effffbb342a021a81e5e5eb36286eff8545833
ssdeep: 12288:l3TD4DnRfwKl+jGH4Hkrf6M4U3RlR4jcyjuPbGuqdMKZQ/2E0f8:9TQuKl+jYJ76MdjR4jcy+K+wQRt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Fynloski.A also known as:

BkavW32.DarkKometJ.Trojan
DrWebBackDoor.Tordev.9
MicroWorld-eScanGen:Trojan.Heur.PK0@rif4XbiS
FireEyeGeneric.mg.621d4055fc8ff4d6
CAT-QuickHealBackdoor.Fynloski.A9
VIPREBackdoor.Win32.Fynloski.A (v)
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.Heur.PK0@rif4XbiS
Cybereasonmalicious.5fc8ff
TrendMicroBKDR_FYNLOS.SMM
BitDefenderThetaAI:Packer.ED9ADB1D1C
CyrenW32/Fynloski.FWDO-2352
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
ClamAVWin.Trojan.DarkKomet-1
GDataGen:Trojan.Heur.PK0@rif4XbiS
KasperskyBackdoor.Win32.DarkKomet.aceg
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
AvastMSIL:GenMalicious-CHX [Trj]
SophosTroj/Fynlosk-AK
ComodoBackdoor.Win32.Agent.XAB@4of2bc
F-SecureBackdoor.BDS/Backdoor.Gen
BaiduWin32.Backdoor.Agent.l
ZillyaBackdoor.DarkKomet.Win32.30209
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.jc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Fynloski (A)
F-ProtW32/Fynloski.BA
JiangminBackdoor/DarkKomet.lue
AviraBDS/Backdoor.Gen
KingsoftVIRUS_UNKNOWN
Endgamemalicious (high confidence)
ArcabitTrojan.Heur.E1D8EC
ZoneAlarmBackdoor.Win32.DarkKomet.aceg
MicrosoftBackdoor:Win32/Fynloski.A
McAfeeArtemis!621D4055FC8F
MAXmalware (ai score=88)
VBA32Backdoor.Tordev
MalwarebytesSpyware.KeyLogger
ZonerTrojan.Win32.77859
ESET-NOD32Win32/Fynloski.AM
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingBackdoor.Darkcomet!8.1117F (C64:YzY0Ov9ZILluoCh9)
YandexTrojan.Comet.Gen.LO
IkarusBackdoor.Win32.DarkKomet
FortinetW32/Generic.AC.1775!tr
AVGMSIL:GenMalicious-CHX [Trj]
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360HEUR/QVM41.1.0943.Malware.Gen

How to remove Backdoor:Win32/Fynloski.A?

Backdoor:Win32/Fynloski.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment