Trojan

Trojan.Win32.Fsysna.fyle malicious file

Malware Removal

The Trojan.Win32.Fsysna.fyle is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Fsysna.fyle virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic

Related domains:

rusav1.icu

How to determine Trojan.Win32.Fsysna.fyle?


File Info:

crc32: FF343BD6
md5: 17a1f7e98731df9b74b98accb650d50e
name: tt.txt
sha1: 64a96c0cfd3884f682b1b56f3e9e1b880849694f
sha256: 3ef2a739073edef534d6bbd2c426cf8e2285544d03afe33ce64526f3e5926248
sha512: 49ad8edbd470c2fd32a1317288634b6411da106510527117808b3c2eb78685c1ceb69d93eaa2047cabce5bb7da9901a00c10e071f7482d2ee5bb6af231380917
ssdeep: 6144:n6Mld0mZO7xKwkN4hzWxXAjHO4aoi8yij67LHMtBhqjeicA:ntlZQxRkN4hyxwbx0ctjbX
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9. All rights reserved. Oracle
InternalName: Crushing Driveclone's
CompanyName: Oracle
FileDescription: Passmark Sells Pictorial Csv Certcli
LegalTrademarks: Copyright xa9. All rights reserved. Oracle
Comments: Passmark Sells Pictorial Csv Certcli
ProductName: Crushing Driveclone's
Languages: English
ProductVersion: 8.4.48.4
PrivateBuild: 8.4.48.4
Translation: 0x0409 0x04b0

Trojan.Win32.Fsysna.fyle also known as:

DrWebTrojan.DownLoader30.50412
MicroWorld-eScanTrojan.GenericKD.32787857
FireEyeGeneric.mg.17a1f7e98731df9b
Qihoo-360Win32/Trojan.0ad
ALYacTrojan.Agent.Fsysna
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Fsysna.tqXg
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32787857
K7GWRiskware ( 0040eff71 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.33556.tmKfamW3Vdli
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.32787857
KasperskyTrojan.Win32.Fsysna.fyle
NANO-AntivirusTrojan.Win32.Dwn.gkqqfz
Ad-AwareTrojan.GenericKD.32787857
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.XPACK.knbgg
ZillyaTrojan.Fsysna.Win32.19052
TrendMicroTROJ_GEN.R002C0PL819
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.32787857 (B)
IkarusTrojan-Ransom.GandCrab
CyrenW32/Trojan.RGRM-4181
JiangminTrojan.Fsysna.koi
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.knbgg
Antiy-AVLTrojan/Win32.Fsysna
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D1F44D91
ZoneAlarmTrojan.Win32.Fsysna.fyle
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C3613566
Acronissuspicious
McAfeeRDN/Generic.tfr
MAXmalware (ai score=100)
VBA32Trojan.Fsysna
MalwarebytesTrojan.Renard
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.GZIC
TrendMicro-HouseCallTROJ_GEN.R002C0PL819
YandexTrojan.Fsysna!
SentinelOneDFI – Suspicious PE
FortinetW32/Fsysna.EXCTUKW!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.74728231.susgen

How to remove Trojan.Win32.Fsysna.fyle?

Trojan.Win32.Fsysna.fyle removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment