Categories: SpyTrojan

TrojanSpy:Win32/Fsysna.RL!MTB removal instruction

The TrojanSpy:Win32/Fsysna.RL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Fsysna.RL!MTB virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:Win32/Fsysna.RL!MTB?


File Info:

crc32: 866AF8ABmd5: 1255eb3e81ec17d030da6884e0d3c724name: 1255EB3E81EC17D030DA6884E0D3C724.mlwsha1: 37c6026c74ca0df996a2ccd303f1dee6e73c46f2sha256: 9bc75c69ead3c8ae7297911c3603cecc3f3d3c739cd5ebb60b111af1939c6952sha512: 3017d6f3515d5ffdf7f8dfcbfe73ab8bbff2d2bce2a94fabbd76a7ff41d3f29ecd3b886c615e88ed8e43d48a54b473c9915c95c7d89388182d0f20ce14a59212ssdeep: 49152:nDKjzxW2w4+KSz9ndpkT6IH/jLh1BqDS9E7taZlrVJOcQ:DKjzxW2w4+KSz9ndpkT6IH/jLh1BqDStype: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Fsysna.RL!MTB also known as:

Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Autoruns.GenericKD.43931772
FireEye Trojan.Autoruns.GenericKD.43931772
ALYac Trojan.Ransom.Blocker.gen
Cylance Unsafe
VIPRE Trojan.Win32.Generic.pak!cobra
K7AntiVirus Spyware ( 005438001 )
BitDefender Trojan.Autoruns.GenericKD.43931772
K7GW Spyware ( 005438001 )
Cybereason malicious.e81ec1
Symantec Trojan.Gen.MBT
APEX Malicious
Avast Win32:Dh-A [Heur]
ClamAV Win.Trojan.Darkkomet-7101816-0
Kaspersky Trojan-Ransom.Win32.Blocker.lvzt
Alibaba TrojanSpy:Win32/Blocker.1809567c
NANO-Antivirus Trojan.Win32.Blocker.fobsgl
AegisLab Trojan.Win32.Blocker.4!c
Ad-Aware Trojan.Autoruns.GenericKD.43931772
Sophos Mal/Generic-S
Comodo Malware@#1x7ejy761tlfh
F-Secure Heuristic.HEUR/AGEN.1102515
DrWeb Trojan.DownLoader27.39796
Zillya Trojan.Blocker.Win32.45678
Invincea Mal/Generic-S
McAfee-GW-Edition PWS-FCNU!1255EB3E81EC
Emsisoft Trojan.Autoruns.GenericKD.43931772 (B)
Ikarus Trojan-Spy.Agent
eGambit Unsafe.AI_Score_99%
Avira HEUR/AGEN.1102515
MAX malware (ai score=100)
Antiy-AVL Trojan[Ransom]/Win32.Blocker
Kingsoft Win32.Heur.KVM007.a.(kcloud)
Microsoft TrojanSpy:Win32/Fsysna.RL!MTB
Gridinsoft Ransom.Win32.Blocker.vb
Arcabit Trojan.Autoruns.Generic.D29E587C
ZoneAlarm Trojan-Ransom.Win32.Blocker.lvzt
GData Trojan.Autoruns.GenericKD.43931772
Cynet Malicious (score: 85)
McAfee PWS-FCNU!1255EB3E81EC
VBA32 TrojanRansom.Blocker
Malwarebytes Spyware.PasswordStealer
Panda Trj/GdSda.A
ESET-NOD32 a variant of Win32/Spy.Agent.POX
Tencent Win32.Trojan.Fakedoc.Auto
Yandex Trojan.Blocker!50/sLbdIDo8
Fortinet W32/Agent.POX!tr.spy
Webroot W32.Trojan.Gen
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Win32/Trojan.Ransom.971

How to remove TrojanSpy:Win32/Fsysna.RL!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Win32/Spy.Virkonni.F removal instruction

The Win32/Spy.Virkonni.F is considered dangerous by lots of security experts. When this infection is active,…

1 min ago

Should I remove “Backdoor.Farfli.AH”?

The Backdoor.Farfli.AH is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Packed.Win32.Klone.ao removal

The Packed.Win32.Klone.ao is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

NSIS/Injector.CMO removal guide

The NSIS/Injector.CMO is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Trojan.Generic.35762198 malicious file

The Trojan.Generic.35762198 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “Malware.AI.103442785”?

The Malware.AI.103442785 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago