Worm

GenPack:Win32.Worm.Agent.QFF removal guide

Malware Removal

The GenPack:Win32.Worm.Agent.QFF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Win32.Worm.Agent.QFF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Clears web history

How to determine GenPack:Win32.Worm.Agent.QFF?


File Info:

crc32: B11E8687
md5: 7beaeedbe09617fc0c2f1b34dc760e32
name: 7BEAEEDBE09617FC0C2F1B34DC760E32.mlw
sha1: aa84eb3008e95e31c786b6771e52dc1fc21fe168
sha256: 8168a249d58c54007e305c20955fcd108903f9aef13f9d660cde5f68e975b389
sha512: 814c1f93c819d810cf32bb31eb0ffdc38cc2351eac8174eaee3db48a3d2f1d8ad3af531754cf1df418fa1bb2dc0a69fc49542fd55e1487da403a48e014d582d1
ssdeep: 24576:IshfGuJFFjoZmo0K/M8T8bmro1RBizDWzFBocB7o7od:5Fjor0K/M8T8DBinWzffe8d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

GenPack:Win32.Worm.Agent.QFF also known as:

BkavW32.FlyStudioTn.Heur
K7AntiVirusP2PWorm ( 005186c41 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad.28634
CynetMalicious (score: 100)
CMCGeneric.Win32.7beaeedbe0!CMCRadar
CAT-QuickHealTrojan.FlyStudio.UJ
ALYacGenPack:Win32.Worm.Agent.QFF
CylanceUnsafe
ZillyaDownloader.VB.Win32.109320
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/FlyStudio.26270016
K7GWP2PWorm ( 005186c41 )
Cybereasonmalicious.be0961
BaiduWin32.Worm.FlyStudio.hg
CyrenW32/Nuj.A.gen!Eldorado
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.FlyStudio.UE
ZonerTrojan.Win32.36440
APEXMalicious
AvastWin32:EvilEPL [Cryp]
ClamAVWin.Worm.FlyStudio-15
KasperskyTrojan-Downloader.Win32.VB.iyl
BitDefenderGenPack:Win32.Worm.Agent.QFF
NANO-AntivirusTrojan.Win32.VB.streq
ViRobotTrojan.Win32.Downloader.62344
SUPERAntiSpywareTrojan.Agent/Gen-DownLoader
MicroWorld-eScanGenPack:Win32.Worm.Agent.QFF
TencentTrojan.Win32.FakeFolder.t
Ad-AwareGenPack:Win32.Worm.Agent.QFF
SophosML/PE-A + Mal/EncPk-NB
ComodoWorm.Win32.Autorun.FlyStudio_AG0@1isj0l
F-SecureTrojan-Dropper:W32/Peed.gen!A
BitDefenderThetaAI:Packer.4B21EDEC1D
VIPRETrojan.Win32.Generic!SB.0
TrendMicroWORM_FLYSTUDI.B
McAfee-GW-EditionBehavesLike.Win32.Autorun.tc
FireEyeGeneric.mg.7beaeedbe09617fc
EmsisoftTrojan.Generic (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.VB.hag
WebrootWorm:Win32/Nuj.A
AviraTR/Drop.Agent.qsc
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Downloader]/Win32.VB
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftWorm:Win32/Nuj.A
GridinsoftMalware.Win32.Pack.24374!se
ArcabitGenPack:Win32.Worm.Agent.QFF
AegisLabTrojan.Win32.FlyStudio.l8X1
ZoneAlarmTrojan-Downloader.Win32.VB.iyl
GDataGenPack:Win32.Worm.Agent.QFF
AhnLab-V3Win32/Flystudio.worm.Gen
Acronissuspicious
McAfeeW32/Autorun.worm.dq.gen
MAXmalware (ai score=100)
VBA32Trojan.HLLW.Erun.507
PandaW32/Autorun.JKX
TrendMicro-HouseCallWORM_FLYSTUDI.B
RisingWorm.Win32.Autorun.eyr (CLASSIC)
YandexTrojan.GenAsa!z7MR6btQHEY
IkarusTrojan.Win32.FlyStudio
MaxSecureTrojan.Malware.1096805.susgen
FortinetW32/PckdFlyStudio.gen
AVGWin32:EvilEPL [Cryp]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.7ca

How to remove GenPack:Win32.Worm.Agent.QFF?

GenPack:Win32.Worm.Agent.QFF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment