Malware

Win32/Packed.FlyStudio.AB potentially unwanted information

Malware Removal

The Win32/Packed.FlyStudio.AB potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.FlyStudio.AB potentially unwanted virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity contains more than one unique useragent.
  • Creates a hidden or system file

Related domains:

daohang1.oss-cn-beijing.aliyuncs.com
ocsp.globalsign.com
ocsp2.globalsign.com
dao.3ayl.cn
ocsp.digicert.com
apy6.cn

How to determine Win32/Packed.FlyStudio.AB potentially unwanted?


File Info:

crc32: AB2C6401
md5: 762ed090574b04bfdea74160f2c7058d
name: 762ED090574B04BFDEA74160F2C7058D.mlw
sha1: dcd0f8887565eccfbf2adc88cd7b5ceb0bbffdbc
sha256: e7349cdada717a64dc65c185df76fa0e37062afd0aa46d6f5e0fb8c08d0910c0
sha512: a08ed8ba5f9d46b7f11946d51b7054d3897841782d7af78219aa47e3fbf54f5eafc5d0549a9024d25b392d4a9a7ab06eb520c9a17ce479af6e31cd3751455254
ssdeep: 24576:k75LVlpmjI+f4BpRzoUDAIW6W5CLQqVTjob:kJaNf4kIW5CLRVQb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: GGx4e0bx8f7dx7ad9
FileVersion: 1.0.0.0
CompanyName: GGx4e0bx8f7dx7ad9
Comments: GGx4e0bx8f7dx7ad9
ProductName: GGx4e0bx8f7dx7ad9x77edx4fe1x538bx529bx6d4bx8bd5
ProductVersion: 1.0.0.0
FileDescription: x77edx4fe1x538bx529bx6d4bx8bd5
Translation: 0x0804 0x04b0

Win32/Packed.FlyStudio.AB potentially unwanted also known as:

K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRisktool.Flystudio.16884
CylanceUnsafe
SangforWin.Malware.Zusy-6840460-0
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.87565e
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AB potentially unwanted
APEXMalicious
AvastFileRepMetagen [Malware]
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
BitDefenderThetaGen:NN.ZexaF.34758.2q0@amrXZdmb
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.762ed090574b04bf
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftProgram:Win32/Wacapew.C!ml
GDataWin32.Trojan.PSE.19Q2126
Acronissuspicious
McAfeePUP-XEP-FD
VBA32BScope.Trojan.Ditertag
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R005H0CFG21
RisingTrojan.StartPage!1.BCDF (CLASSIC)
IkarusTrojan.Black
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/PUP_XEP
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Win32/Packed.FlyStudio.AB potentially unwanted?

Win32/Packed.FlyStudio.AB potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment