Backdoor

How to remove “GenPack:Backdoor.Generic.490839”?

Malware Removal

The GenPack:Backdoor.Generic.490839 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Backdoor.Generic.490839 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine GenPack:Backdoor.Generic.490839?


File Info:

name: 2D11EB18F12E685FAE4B.mlw
path: /opt/CAPEv2/storage/binaries/ff11088ffb06f423f39744b8b5cacdf130abb7892211556af6d0de5325320208
crc32: DC513EAB
md5: 2d11eb18f12e685fae4bb628edc6c739
sha1: 73cf09f065c7ba9497298b6e468d42b7ded7b189
sha256: ff11088ffb06f423f39744b8b5cacdf130abb7892211556af6d0de5325320208
sha512: 300bacdd8a603e4b7aa35e87064d081074bafd64ef269887870fec7b9a7a3f0c8a60c8fa0f983ba0f0471f51f2c788bf5da89c611de4c39199721a5b82d02ccd
ssdeep: 24576:gPY3NkUyL9+8nR95ydms+pkgJfzk6Dy1gjBReWXpSFWc+Vd1/NYxgfryuexm:kY3NkUyRXnR9aApXA6Dye6WXcFRAT/Nn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1337512A262EFA369E547087108D59135AE03FCF83A23A24B7E483A2553F71761F15DEC
sha3_384: 87794115a721bd8b1b8b079709506376d8e44316ab96233e9702cc6fad18cfa48edb3c5ee5f34b81d4d836efd427a5d2
ep_bytes: 5253572bdb5056510f849efeffffa56c
timestamp: 1972-12-25 05:33:23

Version Info:

0: [No Data]

GenPack:Backdoor.Generic.490839 also known as:

BkavW32.FlyStudioTn.Heur
tehtrisGeneric.Malware
MicroWorld-eScanGenPack:Backdoor.Generic.490839
FireEyeGeneric.mg.2d11eb18f12e685f
McAfeeW32/Autorun.worm.lv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Backdoor.Generic.490839
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056f78b1 )
BitDefenderGenPack:Backdoor.Generic.490839
K7GWTrojan ( 0056f78b1 )
Cybereasonmalicious.8f12e6
CyrenW32/Nuj.A.gen!Eldorado
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.OGX
TrendMicro-HouseCallWORM_FLYSTUDI.B
AvastWin32:Evo-gen [Trj]
KasperskyWorm.Win32.FlyStudio.ih
NANO-AntivirusTrojan.Win32.FlyStudio.dszdon
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
EmsisoftApplication.Generic (A)
F-SecureTrojan-Dropper:W32/Peed.gen!A
DrWebWin32.HLLW.Autoruner.26035
ZillyaTrojan.FlyStudio.Win32.5513
TrendMicroWORM_FLYSTUDI.B
McAfee-GW-EditionBehavesLike.Win32.Triusor.tc
Trapminemalicious.high.ml.score
SophosMal/EncPk-NB
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.erbe
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Backdoor]/Win32.FlyAgent
MicrosoftBackdoor:Win32/FlyAgent.F
XcitiumTrojWare.Win32.Agent.btho@2e68po
ArcabitGenPack:Backdoor.Generic.D77D57
SUPERAntiSpywareTrojan.Agent/Gen-XPFraud
ZoneAlarmWorm.Win32.FlyStudio.ih
GDataGenPack:Backdoor.Generic.490839
CynetMalicious (score: 100)
AhnLab-V3Win32/Flystudio.worm.Gen
Acronissuspicious
BitDefenderThetaAI:Packer.19823E521F
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
VBA32BScope.TrojanDownloader.FlyStudio
Cylanceunsafe
APEXMalicious
TencentMalware.Win32.Gencirc.10b380dd
MaxSecureNot-a-Virus.FlyStdio
FortinetW32/PckdFlyStudio.gen
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove GenPack:Backdoor.Generic.490839?

GenPack:Backdoor.Generic.490839 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment