Risk

About “RiskTool.Win32.FlyStudio.cvye” infection

Malware Removal

The RiskTool.Win32.FlyStudio.cvye is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.FlyStudio.cvye virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine RiskTool.Win32.FlyStudio.cvye?


File Info:

name: 7D0516B0FB3D9207CC31.mlw
path: /opt/CAPEv2/storage/binaries/1ee60ad1ba1b80586e3ff6b67cc58a9165d6ade544df9449adc0f51d0c4e0bc0
crc32: 51588EC5
md5: 7d0516b0fb3d9207cc31b5da339600f8
sha1: 2a83338b555583edf415497cf821f58126bd408d
sha256: 1ee60ad1ba1b80586e3ff6b67cc58a9165d6ade544df9449adc0f51d0c4e0bc0
sha512: 70ef32b7fd331786ce06f2c999ef177d367bd613e404e1ee4cc5f5599ac95548d6b40e483ebd04cf11408f13d042d3938392ee54cc7377c4b3080b7139c95e0a
ssdeep: 49152:tHlqZ09k9xwN/4jbTX+lDfOwQ3/VZHQ5t/jfKo2/dgm4on4/:7q8sbqlMvVZHQ5t/jfvsKeQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB661823E103C055E16D2AB032B6473C69709AB09D7989A3EFF4EDB17E7953287D660C
sha3_384: 6b2f299dcfe18b1353143389f8868edbedaf1693cc222a96cb40bcbf55fbe36e0ed18f19ba531fc4dcb659b89413dc6b
ep_bytes: 558bec6aff68882ca200684499850064
timestamp: 2023-08-04 18:27:44

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 玩家EXE
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

RiskTool.Win32.FlyStudio.cvye also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lIa2
Elasticmalicious (high confidence)
ClamAVWin.Malware.Trojanx-9951053-0
FireEyeGeneric.mg.7d0516b0fb3d9207
CAT-QuickHealTrojan.Sabsik
McAfeeArtemis!7D0516B0FB3D
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.36350.@t0@a8KmxFjH
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AC potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.FlyStudio.cvye
AvastWin32:TrojanX-gen [Trj]
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1KQMTX4
JiangminPacked.Vemply.ih
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ZoneAlarmnot-a-virus:RiskTool.Win32.FlyStudio.cvye
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3Malware/Win.Generic.R522123
VBA32BScope.Trojan.Tiggre
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CHF23
RisingHackTool.FlyStudio!8.1222 (TFE:5:8SYVUuV1jGI)
IkarusPUA.BlackMoon
FortinetW32/CoinMiner.ELG!tr.pws
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.0fb3d9
DeepInstinctMALICIOUS

How to remove RiskTool.Win32.FlyStudio.cvye?

RiskTool.Win32.FlyStudio.cvye removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment