Risk

Should I remove “RiskWare.FlyStudio”?

Malware Removal

The RiskWare.FlyStudio is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.FlyStudio virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system

How to determine RiskWare.FlyStudio?


File Info:

crc32: 92FF7A6B
md5: 0c46c63be282abb811ff43be5eb88538
name: qyginstall_pc10109.exe
sha1: 7f9997af7073f3e0276f61e2e508d700217049fb
sha256: 47cbf21119e3ede626d7b1c58e26939349c9adba39b1ee3164775264713e489d
sha512: a681305a8891e2a3a45650189eae6b17dc629052d54dd89eaca688c2213b390b2e6aab057d813c8bc945f70c34a5acb0f30891e639f1f9b969fd39002b87cd76
ssdeep: 98304:O6E5btt4rwyi0+WH/h5qmn9/6NgYwxx0JGGYVnG:25X8Bh5q1Ngv30JGGYVG
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x672cx8ba1x7b97x673ax7a0bx5e8fx53d7x7248x6743x6cd5x548cx56fdx9645x6761x7ea6x4fddx62a4xff0cx5982x672ax7ecfx6388x6743x800cx64c5x81eax4feex6539x3001x7834x574fx672cx7a0bx5e8fxff08x6216x8005x5176x4e2dx4efbx4f55x90e8x5206xff09x5c06x53d7x5230x4e25x5389x7684x5211x4e8bx53cax6c11x4e8bx5236x88c1xff0cx5e76x5728x6cd5x5f8bx5141x8bb8x7684x8303x56f4x5185x53d7x5230x6700x5927x53efx80fdx7684x8d77x8bc9x3002x672cx8ba1x7b97x673ax7a0bx5e8fx4e2dx7684x90e8x5206x8d44x6e90x6765x6e90x7f51x7edcxff0cx7248x6743x5c5ex4e8ex4f5cx8005xff0cx5982x6709x4e0dx5f53xff0cx8bf7x8054x7cfbx6211x4eecx7ea0x6b63x6216x5220x9664x3002
FileVersion: 2.8.0.0
CompanyName: x5947x5f02x679cx8f6fx4ef6x52a9x624b
Comments: x5947x5f02x679cx8f6fx4ef6x52a9x624b
ProductName: QygInstall
ProductVersion: 2.8.0.0
FileDescription: x5947x5f02x679cx8f6fx4ef6x52a9x624b - x5b89x88c5x7a0bx5e8f
Translation: 0x0804 0x04b0

RiskWare.FlyStudio also known as:

CylanceUnsafe
ESET-NOD32a variant of Win32/FlyStudio.Packed.AD potentially unwanted
AvastWin32:Malware-gen
ClamAVWin.Malware.Zusy-6840460-0
NANO-AntivirusTrojan.Win32.StartPage1.grvils
RisingTrojan.Crypto!8.364 (CLOUD)
Endgamemalicious (moderate confidence)
F-SecureTrojan.TR/Crypt.ZPACK.ozglr
DrWebTrojan.StartPage1.58588
Invinceaheuristic
McAfee-GW-EditionArtemis
SentinelOneDFI – Malicious PE
SophosGeneric PUA HP (PUA)
APEXMalicious
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.ozglr
Antiy-AVLGrayWare/Win32.FlyStudio.a
TotalDefenseWin32/Oflwr.A!crypt
McAfeeArtemis!0C46C63BE282
MalwarebytesRiskWare.FlyStudio
IkarusTrojan.Win32.Scar
eGambitUnsafe.AI_Score_100%
FortinetRiskware/FlyStudio_Packed
AVGWin32:Malware-gen

How to remove RiskWare.FlyStudio?

RiskWare.FlyStudio removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment