Trojan

How to remove “Trojan.Mofksys.A”?

Malware Removal

The Trojan.Mofksys.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Mofksys.A virus can do?

  • Executable code extraction
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Mofksys.A?


File Info:

crc32: 4B818126
md5: 48ddbba7a9cd0a043f6d0570e5e5da3d
name: rbxfpsunlocker.exe
sha1: 8275bdecf2907b9269bf8a7a9f0bed31c58b098e
sha256: 853ac20d8cc3712ad411c28f5fea9b489a972cb47e94cc6d2dde7fc0cc0fe8d7
sha512: ee84f7f665d2657767ffbd6756b8064b463a3ab75b71fca70d8b63f1b4ad5ffa10aa94deca80f8b62d9c2eba944dce246cc749bdcf2044d775b1a624b7787b10
ssdeep: 12288:sENN+T5xYrllrU7QY6siZq+7c393w//2MJo/zotyx:I5xolYQY6sQp7cNA//2AGzoq
type: MS-DOS executable, MZ for MS-DOS

Version Info:

Translation: 0x0409 0x04b0
InternalName: Win
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Win
ProductVersion: 1.00
OriginalFilename: Win.exe

Trojan.Mofksys.A also known as:

BkavW32.VB.Swisyn.PE
MicroWorld-eScanWin32.Gosys.A
FireEyeGeneric.mg.48ddbba7a9cd0a04
CAT-QuickHealTrojan.Mofksys.A
McAfeeW32/Swisyn.ag
MalwarebytesTrojan.VBCrypt
VIPRETrojan-PWS.Win32.VB.cu (v)
SangforMalware
K7AntiVirusTrojan ( 0040f0591 )
BitDefenderWin32.Gosys.A
K7GWTrojan ( 0040f0591 )
Cybereasonmalicious.7a9cd0
Invinceaheuristic
BitDefenderThetaAI:Packer.758C9B8320
CyrenW32/VB.AD.gen!Eldorado
SymantecW32.Gosys
TotalDefenseWin32/VB.BOP
BaiduWin32.Trojan.VB.at
TrendMicro-HouseCallPE_MOFKSYS.A
Paloaltogeneric.ml
ClamAVWin.Virus.Sality:1-6335700-1
GDataWin32.Gosys.A
KasperskyTrojan.Win32.Swisyn.bner
AlibabaTrojanPSW:Win32/Swisyn.7c1a2e0b
NANO-AntivirusTrojan.Win32.Swisyn.efyboj
TencentTrojan.Win32.Swisyn.f
Ad-AwareWin32.Gosys.A
SophosTroj/VB-JVT
ComodoTrojWare.Win32.VB.OSKB@4pc2ok
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.Siggen6.54687
ZillyaTrojan.Swisyn.Win32.32298
TrendMicroPE_MOFKSYS.A
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftWin32.Gosys.A (B)
APEXMalicious
F-ProtW32/VB.AD.gen!Eldorado
JiangminTrojan/Swisyn.rmj
WebrootW32.Trojan.Gen
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Swisyn.bner
Endgamemalicious (high confidence)
ArcabitWin32.Gosys.A
ZoneAlarmTrojan.Win32.Swisyn.bner
MicrosoftPWS:Win32/VB.CU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Swisyn.R1452
Acronissuspicious
VBA32MAS.Trojan.VB.01049
ALYacWin32.Gosys.A
PandaGeneric Malware
ZonerTrojan.Win32.47063
ESET-NOD32Win32/VB.OSK
RisingTrojan.QOT!1.6519 (CLOUD)
YandexTrojan.VBGent.Gen.471
IkarusTrojan-Spy.MSIL.Omaneat
eGambitUnsafe.AI_Score_94%
FortinetW32/Swisyn.BNER!tr
AVGWin32:VB-AJKP [Trj]
AvastWin32:VB-AJKP [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM03.0.629B.Malware.Gen

How to remove Trojan.Mofksys.A?

Trojan.Mofksys.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment