Risk

Should I remove “RiskTool.Win32.FlyStudio.cecr”?

Malware Removal

The RiskTool.Win32.FlyStudio.cecr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.FlyStudio.cecr virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

rf13482605-1.icoc.me
ocsp.digicert.com
sj.dy85.cn
statuse.digitalcertvalidation.com

How to determine RiskTool.Win32.FlyStudio.cecr?


File Info:

crc32: 57ADC907
md5: 4deeb8bdc389bdffa0a2a6a7e0e18844
name: 4DEEB8BDC389BDFFA0A2A6A7E0E18844.mlw
sha1: 249c37fdb6db292e6189215d0af651bba81d8eba
sha256: 20984b3177d982a79ca83db0a87d592eaae0446d18275ab1763296566786e2bb
sha512: c4e22f383d980454937f93dcf5d512848d00b1f491dbbe8778863c0ed5dbf397a3f6d3e227e359f103d483f88ee6e74e6be82ec3a4c3a79a34223fbc734f2a58
ssdeep: 12288:BgpJlKpXcgJ9CgDXaVVbCg5sjM2TOHjc7ZCiEkE54jw61xty:BgJKVcgJ9CwaHbps9T9cirE54T1xI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x6613x8bedx8a00x7a0bx5e8f
Translation: 0x0804 0x04b0

RiskTool.Win32.FlyStudio.cecr also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f54a1 )
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0040f54a1 )
Cybereasonmalicious.db6db2
CyrenW32/A-8128ee96!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.FlyStudio.cecr
NANO-AntivirusVirus.Win32.Agent.dvixmz
SUPERAntiSpywareTrojan.Agent/Gen-Injector
SophosMal/Generic-R
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34690.0q0@ayBJ2Uob
TrendMicroTROJ_GEN.R005C0PEH21
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.4deeb8bdc389bdff
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
GridinsoftTrojan.Win32.Gen.bot!i
GDataWin32.Application.PUPStudio.A
AhnLab-V3Malware/Win32.Generic.C230905
Acronissuspicious
McAfeeFlyagent.d
MalwarebytesPUP.Optional.ChinAd
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R005C0PEH21
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazpUYN5FLTpMQJnEl+VaPYI8)
YandexTrojan.GenAsa!sL4lRO6+rqY
IkarusTrojan.Crypt
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.BELF!tr

How to remove RiskTool.Win32.FlyStudio.cecr?

RiskTool.Win32.FlyStudio.cecr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment