Malware

Win32/Fynloski.AA removal instruction

Malware Removal

The Win32/Fynloski.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Fynloski.AA virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Interacts with known DarkComet registry keys
  • Contains RAT configuration for DarkComet (see Static Analysis tab)

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Fynloski.AA?


File Info:

crc32: 9D7B3A8C
md5: 23c3f55a709884aba27bea098d735afc
name: ban.exe
sha1: 0487aab337ecd39f62a30d9441bac4746e3befd8
sha256: 0df18e6ac9e66f40c6166e246a1cd2cee86ca2c90b4d0266227b749f8f78a72f
sha512: 06afe1a622c4f95193000502569815259b1087d8beb7df094d0bd1fd46ba7bbe4dbdbb2494657136d71f599e3de4c5f6de7a27e6fdb114377301446fc948ef07
ssdeep: 24576:AZ1xuVVjfFoynPaVBUR8f+kN10EBuC7uJTj:AQDgok30kK/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Win32/Fynloski.AA also known as:

BkavW32.OnGamesLTKVPOK.Trojan
MicroWorld-eScanTrojan.Inject.AUZ
FireEyeGeneric.mg.23c3f55a709884ab
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric BackDoor.xa
ALYacTrojan.Inject.AUZ
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
SangforMalware
K7AntiVirusBackdoor ( 003b505d1 )
BitDefenderTrojan.Inject.AUZ
K7GWBackdoor ( 003b505d1 )
Cybereasonmalicious.a70988
TrendMicroBKDR_FYNLOS.SMM
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Downloader.C.gen!Eldorado
SymantecBackdoor.Graybird
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastMSIL:GenMalicious-CHX [Trj]
ClamAVWin.Trojan.DarkKomet-1
GDataWin32.Backdoor.DarkComet.H
KasperskyBackdoor.Win32.DarkKomet.xyk
AlibabaBackdoor:Win32/Fynloski.89159368
NANO-AntivirusTrojan.Win32.DarkKomet.dtlfre
TencentBackdoor.Win32.Darkkomet.a
Endgamemalicious (high confidence)
EmsisoftTrojan.Fynloski (A)
ComodoBackdoor.Win32.Agent.XAB@4of2bc
F-SecureBackdoor.BDS/DarkKomet.GS
DrWebBackDoor.Tordev.976
ZillyaBackdoor.DarkKomet.Win32.30208
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cc
MaxSecureBackdoor.DarkComet
Trapminemalicious.moderate.ml.score
CMCBackdoor.Win32.DarkKomet!O
SophosTroj/Backdr-ID
IkarusBackdoor.Win32.DarkKomet
CyrenW32/Downloader.C.gen!Eldorado
JiangminTrojan/Generic.adygq
WebrootW32.Trojan.Gen
AviraBDS/DarkKomet.GS
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet.xyk
ArcabitTrojan.Inject.AUZ
SUPERAntiSpywareBackdoor.Fynloski/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.xyk
MicrosoftBackdoor:Win32/Fynloski.A
AhnLab-V3Win-Trojan/Keylogger.679832
Acronissuspicious
VBA32Backdoor.Tordev
TACHYONBackdoor/W32.DP-DarkKomet.840192
Ad-AwareTrojan.Inject.AUZ
MalwarebytesSpyware.KeyLogger
PandaTrj/Packed.B
ZonerTrojan.Win32.61982
ESET-NOD32Win32/Fynloski.AA
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingBackdoor.Pontoeb!1.6637 (CLASSIC)
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.25E!tr
BitDefenderThetaAI:Packer.77DFE0321C
AVGMSIL:GenMalicious-CHX [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.DarkKomet.A

How to remove Win32/Fynloski.AA?

Win32/Fynloski.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment