Trojan

Should I remove “Trojan.Win32.Fsysna.eabk”?

Malware Removal

The Trojan.Win32.Fsysna.eabk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Fsysna.eabk virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Appends a known multi-family ransomware file extension to files that have been encrypted
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Fsysna.eabk?


File Info:

crc32: F8776D6A
md5: 0d448c04a549f536f7733da43e83e64f
name: 0D448C04A549F536F7733DA43E83E64F.mlw
sha1: 89b448a56c14f4c4998fd17d5d52ed1c29221278
sha256: 143f441feec16d96d05a70f570d85f22944f4c67e55cf1c2b6c15f1e0edad608
sha512: da5599a8fc025727bc0282142e2717018d51919d25cba57e47438c0f1ffcc406312abd0cecb47f2f95ea216cad49c71e481aba7b07ad03790dceaab8f410970f
ssdeep: 384:fvo2I0eqR4F+SSK3Fl2Bm3fZadcwmY1fogk0zbN/9btVNinWy7u:fvoseqR4FIiFgwoZmoCcZQxu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. Todos os direitos reservados.
InternalName: explorer
FileVersion: 6.2.9200.16384 (win8_rtm.120725-1247)
CompanyName: Microsoft Corporation
ProductName: Sistema Operativo Microsoftxae Windowsxae
ProductVersion: 6.2.9200.16384
FileDescription: Explorador do Windows
OriginalFilename: EXPLORER.EXE.MUI
Translation: 0x0816 0x04b0

Trojan.Win32.Fsysna.eabk also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5883
CynetMalicious (score: 100)
ALYacGen:Trojan.Malware.bq0@aifRMwhG
CylanceUnsafe
ZillyaTrojan.Fsysna.Win32.12343
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Fsysna.b8005317
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.4a549f
ESET-NOD32Win32/Filecoder.NIC
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Fsysna-106
KasperskyTrojan.Win32.Fsysna.eabk
BitDefenderGen:Trojan.Malware.bq0@aifRMwhG
NANO-AntivirusTrojan.Win32.Encoder.ehwuux
MicroWorld-eScanGen:Trojan.Malware.bq0@aifRMwhG
TencentWin32.Trojan.Fsysna.Glo
Ad-AwareGen:Trojan.Malware.bq0@aifRMwhG
BitDefenderThetaGen:NN.ZexaF.34126.bq0@aifRMwhG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_ESMERALDA.A
McAfee-GW-EditionGenericRXAZ-FT!0D448C04A549
FireEyeGeneric.mg.0d448c04a549f536
EmsisoftGen:Trojan.Malware.bq0@aifRMwhG (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Fsysna.fqd
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.1BE1259
MicrosoftRansom:Win32/Apocalypse.A!bit
GDataWin32.Trojan-Ransom.Apocalypse.B
AhnLab-V3Trojan/Win32.Fsysna.R189238
McAfeeGenericRXAZ-FT!0D448C04A549
MAXmalware (ai score=100)
VBA32Trojan.Fsysna
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_ESMERALDA.A
RisingTrojan.Generic@ML.100 (RDML:19QfDaeZDpZ8Aar0As/4GA)
YandexTrojan.GenAsa!BW9c/171SvY
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AC.39C76D!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Fsysna.eabk?

Trojan.Win32.Fsysna.eabk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment