Risk

RiskTool.Win32.FlyStudio information

Malware Removal

The RiskTool.Win32.FlyStudio is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.FlyStudio virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

Related domains:

www.123cha.com
ocsp.globalsign.com
opendata.baidu.com
crl2.alphassl.com
ocsp2.globalsign.com

How to determine RiskTool.Win32.FlyStudio?


File Info:

crc32: D26F86E5
md5: 887980d58c3f9a63db2cb83bd060f4f5
name: 887980D58C3F9A63DB2CB83BD060F4F5.mlw
sha1: 6f0cb5508149d4391d8e13043cdf485064370ce7
sha256: 95c581e8eb85e021f7fc5af79349c92a6f721a4999699496d7cda758cc9d5bf7
sha512: 16c3c72ed70c01f90f29ed16e92d41a9426338257aacae0dcb30dc8b8a8fc2c9c86bbcbf66ae120ed7530d53aa0511e4d6d395104bef622b111f0bce58888dcd
ssdeep: 24576:b7RQNks1Gu7zxW5fjRDcxJT90wU8907bO:bsI5f2xJOn89
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 360wjian
FileVersion: 1.0.0.0
CompanyName: wjian
Comments: wjian
ProductName: wjian
ProductVersion: 1.0.0.0
FileDescription: wjian
Translation: 0x0804 0x04b0

RiskTool.Win32.FlyStudio also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.08149d
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastFileRepMetagen [Malware]
Kasperskynot-a-virus:HEUR:RiskTool.Win32.FlyStudio.gen
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34738.tz0@aiuS5zbb
McAfee-GW-EditionBehavesLike.Win32.BadFile.th
FireEyeGeneric.mg.887980d58c3f9a63
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.19Q2126
Acronissuspicious
VBA32BScope.Trojan.Casur
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R005H07FE21
RisingTrojan.Generic@ML.99 (RDML:l5ZEd1nGDX1biMevB6RuGA)
IkarusTrojan.Black
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FlyStudio
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove RiskTool.Win32.FlyStudio?

RiskTool.Win32.FlyStudio removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment