Malware

Win32/Fasong.A removal instruction

Malware Removal

The Win32/Fasong.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Fasong.A virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Created a service that was not started
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Fasong.A?


File Info:

crc32: 2C3CAA7E
md5: 6b699598d9b88107f16ea4977a39dd2c
name: 6B699598D9B88107F16EA4977A39DD2C.mlw
sha1: 28ae2c9fe6ae8ca1e891d32094e159684363cef1
sha256: de048753f687a726312de3ad7f8f0e05966fdd5207942d4a4a82488ff2936248
sha512: 668ca675242b843f7781df225c4156b2b7722b7f7a5afe9233e45ff587546ac5d35f282f43fc518228ae7591290f4bb0da5aada839bcfe1ee255f98c694d0050
ssdeep: 3072:KhS7VD4/EnzzMUD8u8EC45xRS5b7lIf3GYHfqR1hAtTD5DyXglREK0c:dOizzb8uDxZCHlIZgEh5DyXglh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Fasong.A also known as:

K7AntiVirusTrojan ( 0048b81e1 )
DrWebWin32.HLLW.Fasong.1
MicroWorld-eScanTrojan.GenericKD.43115603
CMCWorm.Win32.Fasong!O
ALYacTrojan.GenericKD.43115603
CylanceUnsafe
ZillyaWorm.Fasong.Win32.1
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Fasong.41e9d492
K7GWTrojan ( 0048b81e1 )
Cybereasonmalicious.8d9b88
TrendMicroWORM_FASONG.A
BaiduWin32.Trojan-PSW.OLGames.bm
CyrenW32/Fasong.DIWC-8572
ESET-NOD32Win32/Fasong.A
APEXMalicious
TotalDefenseWin32/PSW.QQpass.7001
AvastWin32:Fasong-ASP [Wrm]
ClamAVWin.Worm.A-13
GDataTrojan.GenericKD.43115603
KasperskyTrojan.Win32.Scar.ofhn
BitDefenderTrojan.GenericKD.43115603
NANO-AntivirusTrojan.Win32.Fasong.hmzl
ViRobotWorm.Win32.A.Fasong.406225.A[ASPack]
TencentMalware.Win32.Gencirc.10b4d013
Ad-AwareTrojan.GenericKD.43115603
SophosTroj/Fasong-A
ComodoWorm.Win32.Fasong.A@3ep7
F-SecureWorm.WORM/Fasong.A
BitDefenderThetaAI:Packer.9DB3747521
VIPREWorm.Win32.Fasong.a (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PWSQQPass.dh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.6b699598d9b88107
EmsisoftTrojan.GenericKD.43115603 (B)
SentinelOneDFI – Suspicious PE
F-ProtW32/Fasong.A
Endgamemalicious (high confidence)
AviraWORM/Fasong.A
eGambitUnsafe.AI_Score_90%
Antiy-AVLWorm/Win32.Fasong
MicrosoftWorm:Win32/Fasong
JiangminTrojan/Hiddukel.e
ArcabitTrojan.Generic.D291E453
AegisLabWorm.Win32.Fasong.lzQk
ZoneAlarmTrojan.Win32.Scar.ofhn
AhnLab-V3Trojan/Win32.QQPass.R57556
Acronissuspicious
McAfeeW32/Fasong.worm
MAXmalware (ai score=82)
VBA32TScope.Trojan.Delf
PandaTrj/Fasong
TrendMicro-HouseCallWORM_FASONG.A
RisingTrojan.QQpass7 (CLOUD)
YandexWorm.Fasong!mw5Muxy+vN4
IkarusWorm.Win32.Fasong
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Fasong.A!tr
AVGWin32:Fasong-ASP [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.PSW.GameOnline.GM

How to remove Win32/Fasong.A?

Win32/Fasong.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment