Risk

Risktool.Flystudio.5361 removal instruction

Malware Removal

The Risktool.Flystudio.5361 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Risktool.Flystudio.5361 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

mcres.net
api.nullcraft.org
ocsp.digicert.com
docs.nullcraft.org
www.bing.com

How to determine Risktool.Flystudio.5361?


File Info:

crc32: 08122EA3
md5: 9afe0b58e4f3c04cfb9c052163541ee4
name: 9AFE0B58E4F3C04CFB9C052163541EE4.mlw
sha1: 669ecefe1e5d0bb193ff5f07f95682f37aea2594
sha256: bb6ac23702a8ff92f9f3ce31e8bcd4e8d8a8310f285ac09bac8e710188dcbe38
sha512: 1afbe4f2bdfe92b957f27462389c504bc51082a6dabfd19a7dae76c7b6964ae7a55f579cf244494d997bc64ab0cb8e1f811df3a29f3212a92514e6b8b8ef4f8b
ssdeep: 24576:tGDStnt22BxCWzMAFkqky0/89H2YHRiMHZgKw4kCA3b+DhUy1hI0X8drX0unYQ8M:tVMAOJy0/899CBbI1hj8lX0kYQ8CLb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7075x5de5x827a x7248x6743x6240x6709
FileVersion: 1.5.5.606
CompanyName: x7075x5de5x827a
Comments: NullCraft Minecraft Server Lite
ProductName: x7075x5de5x827ax6211x7684x4e16x754cx300cx8f7bx300dx5f00x670dx5668
ProductVersion: 1.5.5.606
FileDescription: x7075x5de5x827ax6211x7684x4e16x754cx300cx8f7bx300dx5f00x670dx5668
Translation: 0x0804 0x04b0

Risktool.Flystudio.5361 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRisktool.Flystudio.5361
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.e1e5d0
CyrenW32/Trojan.RYDB-0912
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:MiscX-gen [PUP]
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34738.Wr0@am7Qi8cb
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.9afe0b58e4f3c04c
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Diztakun.ast
eGambitHackTool.Generic
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Tonmye.gen!A
GDataWin32.Trojan.PSE.10CKH4T
AhnLab-V3Trojan/Win.Tonmye.C4471799
McAfeeArtemis!9AFE0B58E4F3
VBA32BScope.Trojan.Glupteba
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R005H01FG21
RisingMalware.Heuristic!ET#82% (RDMK:cmRtazrV2q6UzcEQNJP9EEiK8DP0)
FortinetRiskware/Application
AVGWin32:MiscX-gen [PUP]

How to remove Risktool.Flystudio.5361?

Risktool.Flystudio.5361 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment