Malware

Win32/FlyStudio.Injector.D potentially unwanted removal tips

Malware Removal

The Win32/FlyStudio.Injector.D potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/FlyStudio.Injector.D potentially unwanted virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
www.pfswj.cn
a.tomx.xyz

How to determine Win32/FlyStudio.Injector.D potentially unwanted?


File Info:

crc32: 1C5C8EFE
md5: 14b32c49b999789c7fdd08502da66b25
name: qqprotect___.exe
sha1: d2aac439a43e84065155b9daf47da6282e673fee
sha256: 517aeb9380b236a89fc0015d8fe0f339d24678121dd98c3ae523fdcef9a794f3
sha512: 45cbf3df98e8d3f718bd3c66c5fe1126ef2c93520541217df5266198280073f2e00a085acb91e317c4ba7d5a4d741cca9f651b09bac723d27fa3aa6433adc45f
ssdeep: 12288:LJQGA92loY+DAlwSfw6i1tKaquanvbjXEY:LIElT+caS4b1xquanvPXh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: QQx5b89x5168x9632x62a4x8fdbx7a0bxff08Qx76fexff09
FileVersion: 1.0.0.0
CompanyName: QQx5b89x5168x9632x62a4x8fdbx7a0bxff08Qx76fexff09
Comments: QQx5b89x5168x9632x62a4x8fdbx7a0bxff08Qx76fexff09
ProductName: QQProtectt.exe
ProductVersion: 1.0.0.0
FileDescription: QQx5b89x5168x9632x62a4x8fdbx7a0bxff08Qx76fexff09
Translation: 0x0804 0x04b0

Win32/FlyStudio.Injector.D potentially unwanted also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Trojan.ProcessHijack.Uq0@aGoD!amb
FireEyeGeneric.mg.14b32c49b999789c
CAT-QuickHealTrojan.Kilonepag.25975
McAfeeGenericRXAA-SA!14B32C49B999
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Trojan.ProcessHijack.Uq0@aGoD!amb
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.9b9997
BitDefenderThetaGen:NN.ZexaF.34104.Uq0@aGoD!amb
F-ProtW32/Agent.EW.gen!Eldorado
ESET-NOD32a variant of Win32/FlyStudio.Injector.D potentially unwanted
BaiduWin32.Trojan-Downloader.Agent.cw
AvastWin32:Dropper-OHP [Trj]
ClamAVWin.Malware.Zusy-6840460-0
GDataGen:Trojan.ProcessHijack.Uq0@aGoD!amb
KasperskyHEUR:Trojan.Win32.Generic
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazqkj9Z4k0wr+PHhvA5zpZMI)
Endgamemalicious (high confidence)
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureTrojan.TR/Downloader.Gen
DrWebBackDoor.Siggen.58849
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ProcessHijack.Uq0@aGoD!amb (B)
APEXMalicious
CyrenW32/Agent.EW.gen!Eldorado
JiangminBackdoor/Agent.dcye
AviraTR/Downloader.Gen
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.D!ml
ArcabitTrojan.ProcessHijack.EF439F
ZoneAlarmHEUR:Trojan.Win32.Generic
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Trojan.ProcessHijack.Uq0@aGoD!amb
MAXmalware (ai score=82)
Ad-AwareGen:Trojan.ProcessHijack.Uq0@aGoD!amb
IkarusTrojan-PWS.Win32.QQPass
eGambitUnsafe.AI_Score_100%
FortinetW32/QQWare.A!tr
AVGWin32:Dropper-OHP [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Dropper.73f

How to remove Win32/FlyStudio.Injector.D potentially unwanted?

Win32/FlyStudio.Injector.D potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment