Risk

Risktool.Flystudio.21253 removal tips

Malware Removal

The Risktool.Flystudio.21253 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Risktool.Flystudio.21253 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Risktool.Flystudio.21253?


File Info:

name: 0A5AF9098E0A5971F9E2.mlw
path: /opt/CAPEv2/storage/binaries/88699bc0591a0660155e5f75925d4ad6aa734ef12cc87eba4455ac1077fa52d2
crc32: E83C4D8B
md5: 0a5af9098e0a5971f9e2caff8e0424b2
sha1: c30dbdde9850d5a5d8bc9ce7ef8a4f25116558a4
sha256: 88699bc0591a0660155e5f75925d4ad6aa734ef12cc87eba4455ac1077fa52d2
sha512: 8717d8afcd2882b96ab00ecad8999f1b5169eff6fd7de513b0e8546c500a98b32157e4b647011d4f78632254605096d1f63038a1ed4818023dcde36bbc76fff1
ssdeep: 393216:RL50GNgASffbGWuxvEYlxBYDqkNzuFqDSVbvQb+SsKKU:7KVNivEYHBYGUzuESBvQBL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FE63343E9A8F273D176B6B16C79C2C124B5FC8A696CEA13E7D9B10CE73101538CB616
sha3_384: 90cbe6c686ac7f0df5527d070ef91c3e714d64f8faba88de1fa6531015664a85e40cd545988c8dafea189cb87d371781
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: 此安装程序由 Inno Setup 构建。
CompanyName: 启业软件
FileDescription: 工程投标项目管理系统网络版 Setup
FileVersion: 2.0.0.0
LegalCopyright: 启业软件 版权所有 2006-2012
ProductName: 工程投标项目管理系统网络版
ProductVersion: 2.0.0.0
Translation: 0x0804 0x0000

Risktool.Flystudio.21253 also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Click3.31301
CAT-QuickHealRisktool.Flystudio.21253
SkyhighBehavesLike.Win32.ObfuscatedPoly.vc
McAfeeArtemis!0A5AF9098E0A
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.Click3.kbwqrq
AvastWin32:MalwareX-gen [Trj]
RisingTrojan.Generic@AI.88 (RDML:6p8xWgmblhKScGRTRov/sA)
GDataWin32.Trojan.PSE.Y40FSP (5x)
GoogleDetected
Antiy-AVLRiskWare/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
VaristW32/Trojan.ISO.gen!Eldorado
VBA32BScope.Trojan.MulDrop
IkarusBackdoor.Offend
FortinetRiskware/FlyApplication
AVGWin32:MalwareX-gen [Trj]

How to remove Risktool.Flystudio.21253?

Risktool.Flystudio.21253 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment