Malware

Win32/FlyStudio.Packed.AB potentially unwanted removal guide

Malware Removal

The Win32/FlyStudio.Packed.AB potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/FlyStudio.Packed.AB potentially unwanted virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
do.hf9.net
a.tomx.xyz
www.baidu.com
do.nanzhao.cn

How to determine Win32/FlyStudio.Packed.AB potentially unwanted?


File Info:

crc32: 96B6A30C
md5: 321c54d5c5f8ec6aa5fbb429b8c8cef6
name: suanming.exe
sha1: ca146168083a03004385023aba6fb555ec2ec6a7
sha256: e9be682c097318181944d13afc1214a668f1b7461df10f17c3a29fd10fe49fc2
sha512: ebecfd39456f8102c448326bb1ec8b94679eb096b69eb5914081a3e728d9f4cbe9b3f20b575256f17aaee7b13100371f4e2ae5405340d317400c0982acbe2371
ssdeep: 98304:ifbjYZcsLGvALSGUF041zN8PcjrlGXBFgHd+uXT/yxieYx:+Y+KGvALbbohrvUsdv/yfYx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x90d1x5ddex4e1cx9707x79d1x6280x6709x9650x516cx53f8
FileVersion: 1.0.0.25
CompanyName: x90d1x5ddex4e1cx9707x79d1x6280x6709x9650x516cx53f8
Comments: x4e1cx9707x79d1x6280x7535x5b50x56fe
ProductName: x4e1cx9707x79d1x6280x7535x5b50x56fe
ProductVersion: 1.0.0.25
FileDescription: x4e1cx9707x79d1x6280x7535x5b50x56fe
Translation: 0x0804 0x04b0

Win32/FlyStudio.Packed.AB potentially unwanted also known as:

FireEyeGeneric.mg.321c54d5c5f8ec6a
McAfeeArtemis!321C54D5C5F8
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
K7AntiVirusTrojan ( 005257651 )
K7GWTrojan ( 005257651 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroMal_MLWR-24
BitDefenderThetaGen:NN.ZexaF.34084.@pKdayY!B3bb
F-ProtW32/Downloader.AT.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallMal_MLWR-24
Paloaltogeneric.ml
RisingMalware.Undefined!8.C (C64:YzY0OkLq8gVl8v7R)
Endgamemalicious (high confidence)
ComodoTrojWare.Win32.Trojan.NSPM.~gen@20n73t
VIPREPacker.NSAnti.Gen (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.rc
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
APEXMalicious
CyrenW32/Downloader.AT.gen!Eldorado
MicrosoftTrojan:Win32/Wacatac.C!ml
Acronissuspicious
ESET-NOD32a variant of Win32/FlyStudio.Packed.AB potentially unwanted
YandexPacked/NSPack
IkarusVirus.Win32.Heur
eGambitUnsafe.AI_Score_100%
FortinetRiskware/FlyStudio_Packed
Cybereasonmalicious.8083a0

How to remove Win32/FlyStudio.Packed.AB potentially unwanted?

Win32/FlyStudio.Packed.AB potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment