Trojan

Trojan:Win32/FlyAgent.RG!MTB removal guide

Malware Removal

The Trojan:Win32/FlyAgent.RG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FlyAgent.RG!MTB virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/FlyAgent.RG!MTB?


File Info:

name: C7D577A18FE695C1426D.mlw
path: /opt/CAPEv2/storage/binaries/6caa8f8be73d567433617eacbf721f219552ed0b71e79156f4e320243863ee22
crc32: A81FFAC7
md5: c7d577a18fe695c1426d4e56778adcee
sha1: b1438cdd9f5699732f33376010f99277537edc3f
sha256: 6caa8f8be73d567433617eacbf721f219552ed0b71e79156f4e320243863ee22
sha512: 959352b81681d51fc121a0d7ddfe60e1a38cf52fe164ea573270f5377dd83c18cd596450e8ff02ab9671b442d1638e88e4c9e20d5ade8325312c97f9da9d438f
ssdeep: 24576:gRW3N/0f/oAPoRBchI5anfOlAUAi1K6oElG4lBujFAvCyRL:g5ApamAUAQ/lG4lBmFAvZL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138359E63E69180F5E2581A7016BB2339FE3447450A3BCF87E3D4DD792D72252A7AB20D
sha3_384: 9c690ef854bb45a9c1cf5f1273fb2c8cbf824275296032814ab8bc451cd50b91dfce2ab7253c8afcee031e0dc447bb84
ep_bytes: 558bec6aff6820ae4e0068d4874b0064
timestamp: 2023-07-25 04:41:47

Version Info:

FileVersion: 1.0.0.0
FileDescription: Windows 配置程序
ProductName: Windows 核心进程
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.dywt.com.cn)
Translation: 0x0804 0x04b0

Trojan:Win32/FlyAgent.RG!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.354591
ClamAVWin.Malware.Gotango-7000352-0
CAT-QuickHealTrojanpws.Qqpass.16554
ALYacGen:Variant.Zusy.354591
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Flyagent.Win32.930
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.d9f569
BitDefenderThetaGen:NN.ZexaF.36738.er1@aO6Y@nfb
CyrenW32/FlyAgent.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Flyagent.NGX
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.CMY3U.gen
BitDefenderGen:Variant.Zusy.354591
NANO-AntivirusTrojan.Win32.CMY3U.jyzlcx
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Flyagent.16000183
EmsisoftGen:Variant.Zusy.354591 (B)
F-SecureTrojan.TR/AD.Nekark.vwwpl
VIPREGen:Variant.Zusy.354591
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.c7d577a18fe695c1
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Flyagent.A
JiangminTrojan.Agent.dhal
AviraTR/AD.Nekark.vwwpl
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Zusy.D5691F
ZoneAlarmHEUR:Trojan.Win32.CMY3U.gen
MicrosoftTrojan:Win32/FlyAgent.RG!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Reconyc.R419451
Acronissuspicious
VBA32BScope.Trojan.Dynamer
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Flyagent!1.DAFB (CLASSIC)
YandexTrojan.GenAsa!UMACS2Wk+V8
IkarusTrojan.Win32.FlyAgent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Flyagent.NGX!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/FlyAgent.RG!MTB?

Trojan:Win32/FlyAgent.RG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment