Risk

RiskTool.Win32.FlyStudio.bxtf malicious file

Malware Removal

The RiskTool.Win32.FlyStudio.bxtf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.FlyStudio.bxtf virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine RiskTool.Win32.FlyStudio.bxtf?


File Info:

name: AA553AFDB71F8535E1B2.mlw
path: /opt/CAPEv2/storage/binaries/8f3c82085328134851198d658fca40452c2bed760eabda1d53f484d27937102f
crc32: 78996903
md5: aa553afdb71f8535e1b291d267c21a60
sha1: f286fa73d1344922f8ba9808e74bd16c965b1fb5
sha256: 8f3c82085328134851198d658fca40452c2bed760eabda1d53f484d27937102f
sha512: d6f9d4e6cd65a623c4cbe0d9786843238fcd3955d0325ee6601f6851e79e2ad3794dd9cf45b43315976e19cd8e483bca560c07c6a5bbeeb7a254627f8e0eddc9
ssdeep: 24576:hK+PF0cCN/2+9p8NqGLWJtqCpXwtQmlxQsWcOEYGbUtIYTJemiW6gFQEZTEkQM:hK9E0mAGcFwtLDQsOzNkmiW6gFQE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA851282B244D8D5C40712B1C83ADEF6A056EDBDE176550F255ABF09B8B334331A7E8E
sha3_384: 9708c8816c6bd32a4547b6945f5cd673f0281051204413f6434ec6cbefa070ed98f4b186d2f7699834e9f6c0dee1b599
ep_bytes: 60e8382df3ff0f844704f3ff660fbec0
timestamp: 2012-09-26 07:15:20

Version Info:

FileVersion: 3.0.0.5
FileDescription: 炫舞AA_3.0.5版
ProductName: 炫舞AA辅助
ProductVersion: 3.0.0.5
CompanyName: www.x5aa.com
LegalCopyright: 唯一官网:www.x5aa.com
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

RiskTool.Win32.FlyStudio.bxtf also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.aa553afdb71f8535
SkyhighBehavesLike.Win32.Flyagent.tc
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056e0311 )
K7GWTrojan ( 0056e0311 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.36792.Rz0@aeSVjDgb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
ClamAVWin.Malware.Zusy-6809753-0
Kasperskynot-a-virus:RiskTool.Win32.FlyStudio.bxtf
RisingTrojan.Generic@AI.100 (RDML:SREP6jqtbQXH94SYbOe6IQ)
SophosGeneric ML PUA (PUA)
Trapminemalicious.high.ml.score
IkarusGen.Kelios
GoogleDetected
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Sabsik.RD.A!ml
XcitiumTrojWare.Win32.Agent.ISVQ@5mbonp
ZoneAlarmnot-a-virus:RiskTool.Win32.FlyStudio.bxtf
CynetMalicious (score: 100)
AhnLab-V3Packed/Win32.Vmpbad.C88240
DeepInstinctMALICIOUS
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
AVGWin32:Malware-gen
Cybereasonmalicious.3d1344
AvastWin32:Malware-gen

How to remove RiskTool.Win32.FlyStudio.bxtf?

RiskTool.Win32.FlyStudio.bxtf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment