Malware

About “Win32/Packed.FlyStudio.AA potentially unwanted” infection

Malware Removal

The Win32/Packed.FlyStudio.AA potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.FlyStudio.AA potentially unwanted virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

blog.sina.com.cn

How to determine Win32/Packed.FlyStudio.AA potentially unwanted?


File Info:

crc32: 16E5F8D8
md5: 0445a0399d8e841e0fd6773b21fb11c9
name: WT-JS.exe
sha1: 0046b77df127a2f7e42db2dcafb09cae5d9fb4bd
sha256: 06a15c91a7ade5db7d9707a1c1feac80433d61f9cff600317f29106987b35049
sha512: 41fb1799461997b49ea159c88aaa4a934fe2a2215c795ad3fdb966598a2fd38ddb290176ae2f2b1281358e8acc54547811f2c87278040e0388d3b9e43f43e4ae
ssdeep: 24576:8D22Jxj4hed4OICYzgI9RP+LDo0mvfyvFQQBunOL9fiPWui5///EV1gQ:fo4cddIH/R6D8KvF7N9fCWuK//EY
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Free
FileVersion: 1.6.0.0
CompanyName: NLiger2017
Comments: JScriptx8c03x8bd5x5668
ProductName: WT-JS
ProductVersion: 1.6.0.0
FileDescription: x5c81x6708x65e0x58f0
Translation: 0x0804 0x04b0

Win32/Packed.FlyStudio.AA potentially unwanted also known as:

MicroWorld-eScanGen:Variant.Ursu.44436
ALYacGen:Variant.Ursu.44436
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.99d8e8
Invinceaheuristic
CyrenW32/OnlineGames.HI.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R00AC0WHE18
Paloaltogeneric.ml
GDataGen:Variant.Ursu.44436
KasperskyTrojan-Downloader.Win32.Upatre.gydw
BitDefenderGen:Variant.Ursu.44436
AvastWin32:Malware-gen
Endgamemalicious (moderate confidence)
SophosGeneric PUA AA (PUA)
F-SecureGen:Variant.Ursu.44436
TrendMicroTROJ_GEN.R00AC0WHE18
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Ursu.44436 (B)
SentinelOnestatic engine – malicious
F-ProtW32/OnlineGames.HI.gen!Eldorado
AviraTR/Agent.fgreq
ArcabitTrojan.Ursu.DAD94
ZoneAlarmTrojan-Downloader.Win32.Upatre.gydw
MicrosoftPUA:Win32/Presenoker
McAfeeArtemis!0445A0399D8E
MAXmalware (ai score=99)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
FortinetW32/Generic_PUA_AA
Ad-AwareGen:Variant.Ursu.44436
AVGWin32:Malware-gen
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.Downloader.197

How to remove Win32/Packed.FlyStudio.AA potentially unwanted?

Win32/Packed.FlyStudio.AA potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment