PUA

PUA:Win32/Flystudio removal tips

Malware Removal

The PUA:Win32/Flystudio is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Flystudio virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUA:Win32/Flystudio?


File Info:

name: 64C28E6596442C0F362A.mlw
path: /opt/CAPEv2/storage/binaries/c847341784c1085173f0b1f8abc8733ff8e6747daea516d0fa5e3dd89839af26
crc32: CF0268F8
md5: 64c28e6596442c0f362a5f7ef34abb16
sha1: 9804f0e7e9f560eaae0d94f48ea56c843f8974b5
sha256: c847341784c1085173f0b1f8abc8733ff8e6747daea516d0fa5e3dd89839af26
sha512: 6635706b6f94856a6603a38655352999a16e2f118bfc9bd620d9a86352d19a74123366e657cc70607d650e02e8a091d0c0c10d244ac431b068db27d77be9707a
ssdeep: 24576:q1uXsBzdQErDguqdB2PyTZaqdiXSp0c02uFG6dAk3xMS+Ze:qXQQ3aTZaqdwk0c05HGiB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E375E052B58380B6D656153009F61736FDB89BA10E31FA83D7A0EE7D6E322B1D93701E
sha3_384: ad1a323cada844bdc9f2f97d0c992a6af7f937c5b2ad048d1a3c58be15946d9bd18927b6b3e9576de448ab8e648ac554
ep_bytes: 558bec6aff6880c756006814bd470064
timestamp: 2013-02-18 07:49:46

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

PUA:Win32/Flystudio also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.133168
ClamAVWin.Trojan.Flystudio-9943951-0
FireEyeGeneric.mg.64c28e6596442c0f
SkyhighBehavesLike.Win32.Generic.tc
McAfeeGenericRXAG-NY!64C28E659644
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitTrojan.Midie.D20830
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Midie.133168
EmsisoftApplication.Generic (A)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Midie.133168
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GoogleDetected
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftPUA:Win32/Flystudio
GDataWin32.Trojan.PSE.1S437JY
VaristW32/Trojan.GRW.gen!Eldorado
BitDefenderThetaGen:NN.ZexaF.36792.Kr0@aeIZRxlb
ALYacGen:Variant.Midie.133168
VBA32BScope.Trojan.Tiggre
Cylanceunsafe
YandexTrojan.GenAsa!8JjDvr3E0zg
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
Cybereasonmalicious.7e9f56
DeepInstinctMALICIOUS

How to remove PUA:Win32/Flystudio?

PUA:Win32/Flystudio removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment