Malware

What is “Troj/Inject-FSJ”?

Malware Removal

The Troj/Inject-FSJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Inject-FSJ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Troj/Inject-FSJ?


File Info:

crc32: 5E8D3F04
md5: 36aa21d7674de3ab8aed1fc7f58c68c5
name: lns.exe
sha1: cc5ebe446aa03ef26d0be299240d0b03a79de6d0
sha256: 823d3e4a009254382cf9401cffddeb21e5be60ab5bb283ad325734c8c14cd695
sha512: b3b1ccea8d415baf0b332136099d9907313f25e64ce4148e7c83f606b5b28bd22cd8825844c05a2ffad0c570f1ccc3f1a7e936a5f17a9f33a5fe2b83dab1d521
ssdeep: 24576:dFZmMf48UZ+rT118fhGiv7DFD8JqogqL8bH94MqEvZjlrVgVgJAXzNSdqINDnEQx:dFZD48Ukvn8fYiHJ8JqogqL8bH94MqER
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Gavetwenty Svitla Systems, Inc.* Father Back bettersea Co
InternalName: Pose much
FileVersion: 6.0.88.83
CompanyName: Gavetwenty Svitla Systems, Inc.* Father
BuildID: 43055570
LegalTrademarks: Pose much Red Ar Gavetwenty Svitla Systems, Inc.* Father
ProductName: Pose much
ProductVersion: 6.0.88.83
FileDescription: Pose much
OriginalFilename: driv.exe
Translation: 0x0000 0x04b0

Troj/Inject-FSJ also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.PWS.Siggen2.45605
MicroWorld-eScanTrojan.GenericKD.33564759
Qihoo-360Win32/Trojan.d11
ALYacTrojan.Banker.Gozi
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.33564759
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroTrojanSpy.Win32.URSNIF.THCBEBO
BitDefenderThetaGen:NN.ZexaE.34104.mr0@a0lARgli
F-ProtW32/Ursnif.CQ.gen!Eldorado
Paloaltogeneric.ml
GDataTrojan.GenericKD.33564759
KasperskyTrojan-Banker.Win32.Cridex.kvo
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.33564759
EmsisoftTrojan.Agent (A)
ComodoMalware@#3daqfhvnamag7
F-SecureTrojan.TR/AD.Ursnif.heseo
McAfee-GW-EditionArtemis!Trojan
SophosTroj/Inject-FSJ
IkarusTrojan-Banker.UrSnif
CyrenW32/Trojan.KGYB-2715
WebrootW32.Malware.gen
AviraTR/AD.Ursnif.heseo
Antiy-AVLTrojan[Spy]/Win32.Ursnif
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2002857
ZoneAlarmTrojan-Banker.Win32.Cridex.kvo
MicrosoftTrojanSpy:Win32/Ursnif!MTB
McAfeeArtemis!36AA21D7674D
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Ursnif
PandaTrj/GdSda.A
ESET-NOD32Win32/Spy.Ursnif.CH
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.THCBEBO
RisingSpyware.Ursnif!8.1DEF (CLOUD)
SentinelOneDFI – Suspicious PE
FortinetW32/Ursnif.CH!tr
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]

How to remove Troj/Inject-FSJ?

Troj/Inject-FSJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment