Trojan

About “Trojan-Dropper.Win32.Sysn.czrq” infection

Malware Removal

The Trojan-Dropper.Win32.Sysn.czrq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Sysn.czrq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Trojan-Dropper.Win32.Sysn.czrq?


File Info:

name: 39373AB214AAC9C377E5.mlw
path: /opt/CAPEv2/storage/binaries/361e61c06b56aa828ae28bde89e5082614b30356412d6278f33f69794d6f0054
crc32: 48A90143
md5: 39373ab214aac9c377e5dda14ced3d12
sha1: e208bb14f3d20b50dba24797a8d7d0d643c32bf5
sha256: 361e61c06b56aa828ae28bde89e5082614b30356412d6278f33f69794d6f0054
sha512: da413b561dcd41d1b9b6ac06df98258098d21812929a1f12c662706854b63be91a135ae12beabcb4fe0fac52fa7ec5764f2921d55bec516f151d8e8feb65ad8f
ssdeep: 98304:73M4lvjOUiXhan5pmF1CYcUfrn8S39ZTbAEx/ZzhhHi5LDiB3AJDbEvBqp:40lMUM1tcUTLDnFViBDixAJDovBg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA5623F353782144E0908C39E627FEF871F3079ECF51A874969BF8C52626AD5A292D43
sha3_384: dd19e63d7d90d2a1e2c4d079692b54d7c90a00c0494afa4cb4cd4e2b1672da3e3e75641bdbec8d4f6e0484cbddacf36a
ep_bytes: 688e25d45fe89f63ceff668b06b1da80
timestamp: 2021-11-27 09:57:19

Version Info:

0: [No Data]

Trojan-Dropper.Win32.Sysn.czrq also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.39373ab214aac9c3
McAfeeArtemis!39373AB214AA
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005693e61 )
AlibabaTrojanDropper:Win32/FlyStudio.5c59f87d
K7GWAdware ( 005693e61 )
Cybereasonmalicious.4f3d20
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Packed.AN potentially unwanted
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Sysn.czrq
AvastWin32:Malware-gen
SophosGeneric PUA OC (PUA)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
DrWebTrojan.MulDrop19.8100
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
IkarusTrojan.Win32.Krypt
AviraHEUR/AGEN.1142693
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.@BW@aKlkYIfb
RisingTrojan.Generic@ML.100 (RDML:ZfCQkZJBss/WLMW808tNPw)
YandexTrojan.DR.Sysn!MLPe70T4PPY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FlyStudio_Packed
AVGWin32:Malware-gen

How to remove Trojan-Dropper.Win32.Sysn.czrq?

Trojan-Dropper.Win32.Sysn.czrq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment