Backdoor

Backdoor:Win32/FlyAgent.E removal

Malware Removal

The Backdoor:Win32/FlyAgent.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/FlyAgent.E virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
wjwyg.gnway.net
www.bing.com

How to determine Backdoor:Win32/FlyAgent.E?


File Info:

crc32: B496D920
md5: a7d06f809a7bb8eb913a2c95594fed4b
name: BierS72.exe
sha1: 853414eebde97ea19a22bc310029de84e0896070
sha256: fc9275f57f3dfd8baf411fbd84ff1a7c29b88835e766792d3bc7eb7c4c8493a5
sha512: 8e261c9c4dbc7ccc11a32461a56db9ec9915360bc1805b3315961a403c8440292fa143a854d8220240816117eafe88eb1e5888c9b65afc4960089c4512b4a8f5
ssdeep: 98304:72fVNDFzujfo2+CbNoAHumEldc25/TTCb0Z0g+JB:q0jfoPCbxaLc8uJD
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Backdoor:Win32/FlyAgent.E also known as:

MicroWorld-eScanDropped:Trojan.Spy.FlyStudio.I
nProtectDropped:Generic.Keylogger.2.862DDAC2
CAT-QuickHealWin32.TrojanSpy.Agent.MM.5
McAfeeArtemis!A7D06F809A7B
MalwarebytesBackdoor.PcClient
K7AntiVirusTrojan
K7GWTrojan
NANO-AntivirusRiskware.Win32.Dm.bbnyx
F-ProtW32/Onlinegames.BHW
SymantecWS.Reputation.1
NormanTroj_Generic.CXMPT
TotalDefenseWin32/PcClient.QI
TrendMicro-HouseCallTROJ_GEN.RCBOCLO
AvastWin32:Agent-WYP [Trj]
ClamAVTrojan.Agent-148768
KasperskyTrojan-Dropper.Win32.Flystud.mz
BitDefenderDropped:Trojan.Spy.FlyStudio.I
AgnitumTrojanSpy.Agent!l804h/K15z4
EmsisoftDropped:Trojan.Spy.FlyStudio.I (B)
ComodoBackdoor.Win32.PcClient.~d18
F-SecureTrojan:W32/Malagent.gen!A
DrWebTrojan.Click2.39056
VIPRETrojan.Win32.Generic!BT
AntiVirTR/Dropper.Gen
TrendMicroTROJ_GEN.RCBOCLO
McAfee-GW-EditionArtemis!A7D06F809A7B
SophosW32/SillyFDC-DX
JiangminTrojanSpy.FlyStudio.kh
KingsoftWin32.Hack.AgentT.aq.(kcloud)
MicrosoftBackdoor:Win32/FlyAgent.E
ViRobotBackdoor.Win32.A.Bifrose.223174
AhnLab-V3Trojan/Win32.Bifrose
GDataDropped:Trojan.Spy.FlyStudio.I
CommtouchW32/Onlinegames.OJMH-4535
ESET-NOD32a variant of Win32/FlyStudio.OHA
RisingTrojan.Win32.ECode.j
IkarusTrojan-Spy.Win32.FlyStudio
FortinetW32/Autorun!worm
AVGBackDoor.FlyAgent.F
PandaTrj/Mesgra.B

How to remove Backdoor:Win32/FlyAgent.E?

Backdoor:Win32/FlyAgent.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment