PUA

PUA:Win32/Flystudio removal instruction

Malware Removal

The PUA:Win32/Flystudio is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Flystudio virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PUA:Win32/Flystudio?


File Info:

name: A444B5ADB87DC58F2C98.mlw
path: /opt/CAPEv2/storage/binaries/6f997de019c7a54b715af310f8a6a04ebd25ac3b4b0f5db076607690ecdce42b
crc32: E93E0D22
md5: a444b5adb87dc58f2c9892daf423bba7
sha1: 9e5b2127b572ffdc93bf5588ab44dc55026595b9
sha256: 6f997de019c7a54b715af310f8a6a04ebd25ac3b4b0f5db076607690ecdce42b
sha512: 63c1ca34d83143e978dd5a9ef4e0904e860e172d3309e63e42c28d79bfcad3278269fa11262640c1490d34630903728ebae9df7078cd755625943631b6a38615
ssdeep: 393216:n9NJl3sSGCKHfL+OmspMWNoWDK39eiGGxDyb:nf33srHfaOmsVN/DketGx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136D6332322553883E0DD9C72A723BED1B7B65E7B8E45E93C7CE178C52A31AD4A112353
sha3_384: 6373e609fb501bf647ba8bb525d508bae6ba54ba0c5f747b48a4ae38f8e5dfaa560ad51df93fce4a4a278aca25e83f7f
ep_bytes: 52bab55bbd03e8bdb6030061529a5ca6
timestamp: 2023-10-03 05:22:10

Version Info:

0: [No Data]

PUA:Win32/Flystudio also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
tehtrisGeneric.Malware
SkyhighBehavesLike.Win32.Generic.rc
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaF.36802.@FW@aGJIa3ib
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Packed.AN potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a444b5adb87dc58f
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GoogleDetected
Antiy-AVLGrayWare/Win32.Packed
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
MicrosoftPUA:Win32/Flystudio
VaristW32/ABRisk.ODJE-8560
AhnLab-V3Trojan/Win.Malware-gen.C5106249
McAfeeArtemis!A444B5ADB87D
VBA32BScope.Trojan.Occamy
MalwarebytesFlyStudio.Trojan.Packer.DDS
RisingTrojan.Generic@AI.99 (RDML:CSpU9cfPBsFLsr/e/I2azA)
FortinetRiskware/FlyStudio_Packed
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove PUA:Win32/Flystudio?

PUA:Win32/Flystudio removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment