Malware

What is “Win32/FlyStudio.ONL”?

Malware Removal

The Win32/FlyStudio.ONL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/FlyStudio.ONL virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/FlyStudio.ONL?


File Info:

name: 3C60B05DE3B17894615E.mlw
path: /opt/CAPEv2/storage/binaries/865acb0565ea21b7b84ba9e8dfabad38fd4148c10d7e795ca669ff19c639bd21
crc32: 24CF7B2E
md5: 3c60b05de3b17894615ef7dbc9062e80
sha1: 1466a96d5ba3dc9b0e747c1f7495066e1a18fde3
sha256: 865acb0565ea21b7b84ba9e8dfabad38fd4148c10d7e795ca669ff19c639bd21
sha512: 43784123ad6cd4f8d14ad79bde83e3901d0994b02909a627d4a5519727de4372bbb62464fad86629dcb4b3bd1d7d565609fbaa26e36adc960b14cca20626e30a
ssdeep: 6144:/L8LRZrIAmegoN53rKWJP+q/c8UAzBUFg9te2Qa33r0rbeWqrPel9XzRCIVmKObW:T8DrIBYrKO2WcZAjte2QCVW2QzRCzKP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A9423DF6E852634F9479E314BA62E550C23B35D2F1D3F3B0F46E540A0B26313E95A2A
sha3_384: 7c6726a861ceec53c59b247f8b44af86d3a8cba3f85399ba2b7a0af0c6fb54deafd1148b845353be40716f4131813bcb
ep_bytes: 60be00d04a008dbe0040f5ff5783cdff
timestamp: 2015-02-04 10:59:13

Version Info:

0: [No Data]

Win32/FlyStudio.ONL also known as:

LionicTrojan.Multi.Generic.mbME
Elasticmalicious (moderate confidence)
DrWebTrojan.MulDrop6.42243
ClamAVWin.Malware.Generic-9820446-0
McAfeeArtemis!3C60B05DE3B1
ZillyaBackdoor.PePatch.Win32.64249
CrowdStrikewin/malicious_confidence_60% (D)
VirITTrojan.Win32.Generic.AUCL
CyrenW32/S-70f29df6!Eldorado
SymantecTrojan.Gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/FlyStudio.ONL
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusRiskware.Win32.Adw.dneswh
AvastWin32:Adware-gen [Adw]
F-SecureTrojan.TR/Seodec.abne
BaiduWin32.Adware.Generic.ca
McAfee-GW-EditionGenericRXAG-YI!BCA1FA55392A
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Seodec
AviraTR/Seodec.abne
Antiy-AVLTrojan/Win32.SGeneric
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.Win32.Generic.180C219D (C64:YzY0OhvJxrWCX8vF)
YandexTrojan.Seodec!Xz8zweTpaTY
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove Win32/FlyStudio.ONL?

Win32/FlyStudio.ONL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment