Risk

Risktool.Flystudio.16885 (file analysis)

Malware Removal

The Risktool.Flystudio.16885 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Risktool.Flystudio.16885 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

z.whorecord.xyz
xiaomi.com
a.tomx.xyz

How to determine Risktool.Flystudio.16885?


File Info:

crc32: 3F8ED74F
md5: 8dfe27146c0dcae6305db2492707fbc7
name: xmsjtbgj_v1.0.exe
sha1: 1e3100768ef5ca05f82b89f6bb896f149ddea30c
sha256: d7c4858ff478ae79c6ebb79fec9d6feffbc36acb19fb62d200254067ca3c13d6
sha512: 7b1830cd41fc049fa06dc2252b6c9da20dca2db26fba98aa44f0ad71293c73279a297bd3bff9216695ff136a2762929c931f0f85e8961beef338f0ed80faa97d
ssdeep: 6144:OMgTQgakMDn8jx6LvUeew6fcTrWG0VA4SYuRMtuPFa8woOXbjBJHxs/SBmD:OjQTDexcaw6fc3mTVeFGoO5JRXQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x6613x8bedx8a00x7a0bx5e8f
Translation: 0x0804 0x04b0

Risktool.Flystudio.16885 also known as:

FireEyeGeneric.mg.8dfe27146c0dcae6
CAT-QuickHealRisktool.Flystudio.16885
McAfeeGenericRXEN-IU!8DFE27146C0D
MalwarebytesSpyware.OnlineGames
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.68ef5c
Invinceaheuristic
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Zusy-6840460-0
AlibabaTrojan:Win32/Generic.c4f1a825
NANO-AntivirusTrojan.Win32.FlyStudio.dfxrae
AegisLabTrojan.Win32.Generic.4!c
ComodoWorm.Win32.Dropper.RA@1qraug
ZillyaTrojan.Generic.Win32.929836
TrendMicroTROJ_GEN.R002C0PCT19
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
Trapminesuspicious.low.ml.score
SophosGeneric PUA BO (PUA)
IkarusTrojan-Dropper.Agent
GDataWin32.Application.FlyStudio.F
JiangminTrojan/Generic.bbdyo
MAXmalware (ai score=90)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Win32/Tiggre!rfn
Endgamemalicious (high confidence)
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
VBA32Trojan.Tiggre
CylanceUnsafe
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PCT19
YandexTrojan.Pasta.Gen.1
SentinelOneDFI – Malicious PE
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Risktool.Flystudio.16885?

Risktool.Flystudio.16885 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment