Backdoor

How to remove “Backdoor:Win32/FlyAgent.F”?

Malware Removal

The Backdoor:Win32/FlyAgent.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/FlyAgent.F virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.lzkjwl.xyz
a.tomx.xyz
www.baidu.com

How to determine Backdoor:Win32/FlyAgent.F?


File Info:

crc32: AC9C1C2D
md5: 6c58f2716e5fe3ec7567ebb5d5ef5b0b
name: ziyuanbao.exe
sha1: 19fdd5c91b3424b88a837e3c3bb84939e6f3b0f6
sha256: b4fc7d7cbc10bb8bf3bc08e3ff3eb7ab8fafb61442604b0c0303f842415f0286
sha512: c1a212ee490e187ffcf0ab5869a41ae133c56e3b0a1e08392b09eadfc5552a0b47598874452c6d38f1e193ad7a2208c56d65940e5a062a64879e033fb980d9e9
ssdeep: 49152:CGQdXvrfbRqnPqmghkMaC5tbV0yFEsBYnSxP3jAp:CGQdjTRqYkMtxPFBu03Mp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: www.lzkjwl.xyz
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x8d44x6e90x5b9d
ProductVersion: 1.0.0.0
FileDescription: x5b9ex7528x8d44x6e90x4e00x952ex53d6
Translation: 0x0804 0x04b0

Backdoor:Win32/FlyAgent.F also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Trojan.Heur.RP.mw3@aumiMumb
CylanceUnsafe
VIPRETrojan.Win32.Autorun.dm (v)
SangforMalware
BitDefenderGen:Trojan.Heur.RP.mw3@aumiMumb
K7GWAdware ( 004b8bcf1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroWORM_FLYSTUDI.B
F-ProtW32/Heuristic-162!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Application.PUPStudio.A
AlibabaBackdoor:Win32/FlyAgent.d046d6f2
NANO-AntivirusVirus.Win32.Agent.dvixmz
AegisLabTrojan.Win32.Malicious.4!c
TencentWin32.Trojan.Flystudi.Wqdk
Ad-AwareGen:Trojan.Heur.RP.mw3@aumiMumb
EmsisoftApplication.Generic (A)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Triusor.vc
MaxSecureVirus.Nimnul.E
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.6c58f2716e5fe3ec
SophosMal/EncPk-TB
IkarusTrojan-Dropper.Win32.Flystud
CyrenW32/Heuristic-162!Eldorado
MAXmalware (ai score=89)
Endgamemalicious (high confidence)
ArcabitTrojan.Heur.RP.EA491B
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
MicrosoftBackdoor:Win32/FlyAgent.F
Acronissuspicious
McAfeeFlyagent.d
VBA32Backdoor.FlyAgent
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
TrendMicro-HouseCallWORM_FLYSTUDI.B
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.BELF!tr
BitDefenderThetaAI:Packer.D2F859641F
AVGWin32:Malware-gen
Cybereasonmalicious.16e5fe
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM18.1.59EF.Malware.Gen

How to remove Backdoor:Win32/FlyAgent.F?

Backdoor:Win32/FlyAgent.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment