Trojan

Trojan-Dropper.Win32.Sysn.ciol (file analysis)

Malware Removal

The Trojan-Dropper.Win32.Sysn.ciol is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Sysn.ciol virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan-Dropper.Win32.Sysn.ciol?


File Info:

name: 1F585264E510468BFAF1.mlw
path: /opt/CAPEv2/storage/binaries/98495d0567aae23c23421e20cf52358cff0d4993feafa139806f9f335fed1c8b
crc32: C732F3F0
md5: 1f585264e510468bfaf1af2703713747
sha1: 560882dcd19394117a2af399893d2719a08059a3
sha256: 98495d0567aae23c23421e20cf52358cff0d4993feafa139806f9f335fed1c8b
sha512: a66adfa74e0f66b634232b0a0f77eb0565c12acb4a986e2c90d13b2a6e5e6c8d7cb4445293dca5317fcbcdbca78ba3d5608ca2adb7265c0b95a37437b4ad23dd
ssdeep: 768:ogwwMtr+DJKOf9VS5uEuXQkilyK9fi0FBqF+XajA:ogwFtjxEsfcgMA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11723F813AA585122E36A86B01833D5E95E36BC350052EE072ACAFE5D1C71A43BDF971B
sha3_384: 6620ed122b4fbe7d6293139ee027632585db54d8d648311a9fc7768f4d7a94aea0f7b17522d4ac6b955787c484152de9
ep_bytes: 68541d4000e8f0ffffff000000000000
timestamp: 2007-11-04 15:45:17

Version Info:

Translation: 0x0409 0x04b0
CompanyName: ABHIS
ProductName: IPUPDATOR
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Final
OriginalFilename: Final.exe

Trojan-Dropper.Win32.Sysn.ciol also known as:

LionicTrojan.Win32.Sysn.b!c
MicroWorld-eScanGen:Trojan.VBMalware.dm0@aORIgNoi
FireEyeGen:Trojan.VBMalware.dm0@aORIgNoi
CAT-QuickHealTrojan.SysnVMF.S20641742
McAfeeW32/Generic.p.d
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Sysn.ciol
AlibabaTrojanDropper:Win32/VBMalware.b982de98
BitDefenderThetaAI:Packer.AD31E3911F
SymantecW32.Gosys
APEXMalicious
KasperskyTrojan-Dropper.Win32.Sysn.ciol
BitDefenderGen:Trojan.VBMalware.dm0@aORIgNoi
NANO-AntivirusTrojan.Win32.Sysn.eymyyu
AvastWin32:Malware-gen
TencentWin32.Trojan-dropper.Sysn.Eanw
Ad-AwareGen:Trojan.VBMalware.dm0@aORIgNoi
SophosMal/Generic-S
ComodoMalware@#1ai3wm136yzmg
McAfee-GW-EditionW32/Generic.p.d
EmsisoftGen:Trojan.VBMalware.dm0@aORIgNoi (B)
IkarusTrojan.VB.Downloader
GDataGen:Trojan.VBMalware.dm0@aORIgNoi
JiangminTrojanDropper.Sysn.geu
AviraTR/VB.Downloader.Gen
MAXmalware (ai score=87)
ArcabitTrojan.VBMalware.E7A443
ZoneAlarmTrojan-Dropper.Win32.Sysn.ciol
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
ALYacGen:Trojan.VBMalware.dm0@aORIgNoi
MalwarebytesGeneric.Malware/Suspicious
YandexTrojan.DR.Sysn!yX96CfZXBy0
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.LEI!tr
AVGWin32:Malware-gen
Cybereasonmalicious.4e5104

How to remove Trojan-Dropper.Win32.Sysn.ciol?

Trojan-Dropper.Win32.Sysn.ciol removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment