Trojan

Should I remove “Trojan.Fynloski (A)”?

Malware Removal

The Trojan.Fynloski (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Fynloski (A) virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Contains RAT configuration for DarkComet (see Static Analysis tab)

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Fynloski (A)?


File Info:

crc32: E7D8D624
md5: 8b2343d0b1e7d35b30b402478387da19
name: 1307a1ff56ca7ea5.exe
sha1: 43adb71190172e05cda78a05f8643d0fe7a8c332
sha256: 2ae7eb3e138feab1512929f01d85bec8f2f1f941798f8c994002c479591afccd
sha512: 1bc38d51419909efcc438a1d77825514fdd251ddcfe50223c116ac3cb9d53466f8b773cea467918413315753db75c2204226a371b673363dc93ab80cd92d3478
ssdeep: 12288:i9HMeUmcufrvA3kb445UEJ2jsWiD4EvFuu4cNgZhCiZKD/XdyFL:OiBIGkbxqEcjsWiDxguehC2SI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Trojan.Fynloski (A) also known as:

BkavW32.DarkKometJ.Trojan
DrWebBackDoor.Tordev.9
MicroWorld-eScanGen:Trojan.UserStartup.PK0@aWo3UWeS
FireEyeGeneric.mg.8b2343d0b1e7d35b
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric BackDoor.xa
CylanceUnsafe
ZillyaBackdoor.DarkKomet.Win32.30209
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Trojan.UserStartup.PK0@aWo3UWeS
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.0b1e7d
Invinceaheuristic
BitDefenderThetaAI:Packer.FC9638601C
F-ProtW32/Fynloski.BA
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.DarkKomet-1
GDataGen:Trojan.UserStartup.PK0@aWo3UWeS
KasperskyBackdoor.Win32.DarkKomet.aceg
AlibabaBackdoor:Win32/Fynloski.ede865d9
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
SUPERAntiSpywareBackdoor.Fynloski
AvastMSIL:GenMalicious-CHX [Trj]
RisingBackdoor.Darkcomet!8.1117F (C64:YzY0OpqnL5f+/MEk)
Ad-AwareGen:Trojan.UserStartup.PK0@aWo3UWeS
SophosTroj/Fynlosk-AK
ComodoBackdoor.Win32.Agent.XAB@4of2bc
F-SecureBackdoor.BDS/Backdoor.Gen
BaiduWin32.Backdoor.Agent.l
VIPREBackdoor.Win32.Fynloski.A (v)
TrendMicroBKDR_FYNLOS.SMM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.jh
Trapminemalicious.high.ml.score
EmsisoftTrojan.Fynloski (A)
IkarusBackdoor.Win32.DarkKomet
CyrenW32/Fynloski.FWDO-2352
JiangminBackdoor/DarkKomet.lue
MaxSecureBackdoor.W32.DarkKomet.aagr
AviraBDS/Backdoor.Gen
MAXmalware (ai score=80)
KingsoftWin32.Hack.HuigeziT.cz
Endgamemalicious (high confidence)
ArcabitTrojan.UserStartup.EA80ED
AegisLabTrojan.Win32.DarkKomet.tneT
ZoneAlarmBackdoor.Win32.DarkKomet.aceg
MicrosoftBackdoor:Win32/Fynloski.A
AhnLab-V3Backdoor/Win32.Graybird.R33420
Acronissuspicious
ALYacGen:Trojan.UserStartup.PK0@aWo3UWeS
TACHYONBackdoor/W32.DP-DarkKomet.674304.B
VBA32Backdoor.Tordev
MalwarebytesSpyware.KeyLogger
ZonerTrojan.Win32.77859
ESET-NOD32Win32/Fynloski.AM
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.DarkKomet.zem
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.1775!tr
WebrootW32.Trojan.Gen
AVGMSIL:GenMalicious-CHX [Trj]
PandaTrj/Packed.B
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM05.1.2A2D.Malware.Gen

How to remove Trojan.Fynloski (A)?

Trojan.Fynloski (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment