Trojan

Trojan.Win32.Fsysna.dhqm removal

Malware Removal

The Trojan.Win32.Fsysna.dhqm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Fsysna.dhqm virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan.Win32.Fsysna.dhqm?


File Info:

name: 74EE5ABACA7887DA48B7.mlw
path: /opt/CAPEv2/storage/binaries/914f6ed8f29a991873a20f3c7e43301d7ac1b00b9b0867e80b60646148c5bf49
crc32: E6A8C9B6
md5: 74ee5abaca7887da48b7e431346b48b1
sha1: 2f4d137a7860073e2e8c44409abfe0fc14dd4547
sha256: 914f6ed8f29a991873a20f3c7e43301d7ac1b00b9b0867e80b60646148c5bf49
sha512: b6c781ed26ad8e6f8417f33b994c60a02b1c1734aad813a435da4a0184f3b55ce49403cca7b9c19e4f908895aa44b5abe198881eaed308c879a0666696f61bf1
ssdeep: 6144:Wf+Jjjou35J6i5plrzuo6/LkeYvjoIHnv0RX/VwFdLD/7MsrYMC+9GXL9M8sG3dx:hj8u3ui5pl+uBvc/V0FdYxJdRqM9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191A46D32F3F19433D1331A788D5B93AC982ABE113D28A8467BE91D4C5F39791742B297
sha3_384: 11ea99b61189997649ea7b32ce68f354cdbc9e7f13f650a2b833efeb59f9e8c257dae0296059150ed6a8bd5b53a860b7
ep_bytes: 558bec83c4f0b850554600e8fc18faff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Win32.Fsysna.dhqm also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.359768
CAT-QuickHealWorm.Autorun.RE8
McAfeeW32/Autorun.worm.zi
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.550
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005726171 )
K7GWTrojan ( 005726171 )
Cybereasonmalicious.aca788
BaiduWin32.Worm.Autorun.s
CyrenW32/Worm.ALYD
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.Delf.J
APEXMalicious
ClamAVWin.Worm.Autorun-314
KasperskyTrojan.Win32.Fsysna.dhqm
BitDefenderGen:Variant.Zusy.359768
NANO-AntivirusTrojan.Win32.AutoRun.dzjjvz
SUPERAntiSpywareTrojan.Agent/Gen-Autorun
AvastWin32:AutoRun-AOY [Wrm]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Zusy.359768
TACHYONWorm/W32.DP-AutoRun.483840
SophosML/PE-A + Mal/SillyFDC-A
ComodoWorm.Win32.AutoRun.~ZP@2mkay
DrWebTrojan.Winlock.14301
VIPRETrojan.Win32.Generic!SB.0
TrendMicroMal_Otorun5
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.74ee5abaca7887da
EmsisoftGen:Variant.Zusy.359768 (B)
IkarusWorm.Win32.AutoRun
GDataGen:Variant.Zusy.359768
JiangminWorm/AutoRun.dir
WebrootW32.Autorun.Gen
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3F55
KingsoftHeur.SSC.2722881.1216.(kcloud)
ArcabitTrojan.Zusy.D57D58
MicrosoftWorm:Win32/Autorun.RE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AutoRun.C65764
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34294.DGW@aCpuCyki
ALYacGen:Variant.Zusy.359768
MAXmalware (ai score=81)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.1856542377
TrendMicro-HouseCallMal_Otorun5
RisingWorm.Autorun!1.9D28 (CLASSIC)
YandexTrojan.GenAsa!l9OHG3irraI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Autorun.DJ!worm
AVGWin32:AutoRun-AOY [Wrm]
PandaW32/Autorun.AJK.worm

How to remove Trojan.Win32.Fsysna.dhqm?

Trojan.Win32.Fsysna.dhqm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment