Trojan

Trojan.Win32.Fsysna.geqj information

Malware Removal

The Trojan.Win32.Fsysna.geqj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Fsysna.geqj virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a hidden or system file
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

cosrem.ddnsgeek.com
cosrem.dyndns.org

How to determine Trojan.Win32.Fsysna.geqj?


File Info:

crc32: 6C9C8363
md5: 4dd78454c76c70835352dfb2f2d56baf
name: 4DD78454C76C70835352DFB2F2D56BAF.mlw
sha1: fb1667eb55cd36ac4dd02dfd901f278130b6024c
sha256: 189e665241a7642497940eba5c5199bae7e9fa2d2ba5b49fa0453d88cc91b861
sha512: 2a429c57dd29d0713a7253f3bf9a0dff59288d1949e534fabdf9ec80d0a36e549e0ebfe407c947b20d39b032032264990a4ea9bf1b639ce85425c03f8ee1c06e
ssdeep: 24576:EAT8QE+kPZa7EQIk3TH2Rlu7sXALqh/mnHMufnWE:EAI+SRQTDHQZAWh/msUWE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: ,
FileDescription: PDFelementPatch 1.00 Installation
FileVersion: 1.00
Comments:
CompanyName: ,
Translation: 0x0409 0x04e4

Trojan.Win32.Fsysna.geqj also known as:

BkavW32.RansomwareBHQc.Trojan
K7AntiVirusUnwanted-Program ( 00556f181 )
Elasticmalicious (high confidence)
DrWebTrojan.Nanocore.427
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Patcher
ALYacTrojan.GenericKD.42902290
CylanceUnsafe
SangforTrojan.Win32.PWSX.gen
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:MSIL/Fsysna.d301d14a
K7GWUnwanted-Program ( 00556f181 )
Cybereasonmalicious.4c76c7
CyrenW32/Trojan.TRIX-0883
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Fsysna.geqj
BitDefenderTrojan.GenericKD.42902290
NANO-AntivirusTrojan.Win32.NanoBot.hixmil
MicroWorld-eScanTrojan.GenericKD.42902290
TencentWin32.Trojan.Fsysna.Phqt
Ad-AwareTrojan.GenericKD.42902290
SophosMal/Generic-S
ComodoMalware@#1hiekv5rj2dqc
BitDefenderThetaGen:NN.ZemsilF.34796.Sr0@a0Xcdmf
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.4dd78454c76c7083
EmsisoftTrojan.GenericKD.42902290 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Fsysna.kyj
AviraHEUR/AGEN.1134068
Antiy-AVLTrojan/Generic.ASMalwS.3021739
MicrosoftTrojan:Win32/CommandAndControl!rfn
ZoneAlarmTrojan.Win32.Fsysna.geqj
GDataTrojan.GenericKD.42902290
AhnLab-V3Malware/Win32.Generic.C4063471
McAfeeArtemis!4DD78454C76C
MAXmalware (ai score=83)
VBA32Trojan.Fsysna
MalwarebytesRiskWare.Patcher
PandaTrj/CI.A
IkarusTrojan-Dropper.VBS.Agent
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetRiskware/Fsysna
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Nanocore.HwUBEpsA

How to remove Trojan.Win32.Fsysna.geqj?

Trojan.Win32.Fsysna.geqj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment