Malware

Win32/FlyStudio.ONP information

Malware Removal

The Win32/FlyStudio.ONP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/FlyStudio.ONP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Win32/FlyStudio.ONP?


File Info:

name: 4E11CD603151D320AE06.mlw
path: /opt/CAPEv2/storage/binaries/acf3044c83b59dd8ffbe37b429ce044abbd8ed2daf2039ade65fa83b79678fdb
crc32: 20282A49
md5: 4e11cd603151d320ae069860bc42dd46
sha1: d4b99b5d4622af47c58e4df57e313ba0baf05d8f
sha256: acf3044c83b59dd8ffbe37b429ce044abbd8ed2daf2039ade65fa83b79678fdb
sha512: 9895a682f85e67ffdf4453e8a4f2c8207ffb4c754e87ae988deb0f5eeaff6553ac9db1a17f106457b49233179713d422884c862b72a466c59dd96452dc2d40bb
ssdeep: 24576:OFe+taUO7cUBMum2v/iVgn9ev/8fB2nOKMSb5uPocORzeOmJSEKN:OFa5Aum2niwev/wYOKMauPoc4zA4EKN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131E52310C602A1BCE610AB34E137BEE21D9E35B57E8932290F4CE85D64F15A2ED7CB75
sha3_384: 73d3d8afafe0306285957e7c3a06fadb18cbc55e3ebb1d79b8f0ed954265b33aad3c5786c3a377fb0ea859231c0a090d
ep_bytes: 60be000049008dbe0010f7ff57eb0b90
timestamp: 2013-12-10 13:16:00

Version Info:

FileVersion: 1.0.0.0
FileDescription: -
ProductName: UpDate
ProductVersion: 1.0.0.0
CompanyName: Dlg-
LegalCopyright: -
Comments: -
Translation: 0x0804 0x04b0

Win32/FlyStudio.ONP also known as:

LionicTrojan.Win32.Generic.lEL5
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Graftor.131506
FireEyeGeneric.mg.4e11cd603151d320
ALYacGen:Variant.Graftor.131506
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/FlyStudio.14dfd999
K7GWTrojan ( 005886601 )
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/S-a00d3f39!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/FlyStudio.ONP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agentb.anrc
BitDefenderGen:Variant.Graftor.131506
NANO-AntivirusTrojan.Win32.Agent.ctgsbp
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b4e509
Ad-AwareGen:Variant.Graftor.131506
EmsisoftGen:Variant.Graftor.131506 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.StartPage.61922
ZillyaTrojan.Agentb.Win32.18638
McAfee-GW-EditionBehavesLike.Win32.Generic.vz
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11D15LD
JiangminTrojan.Agentb.hvz
AviraBDS/Agent.depz.2
KingsoftWin32.Hack.Undef.(kcloud)
ViRobotTrojan.Win32.Z.Graftor.3085824
ZoneAlarmTrojan.Win32.Agentb.anrc
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Swisyn.C223507
McAfeeGenericRXAA-AA!4E11CD603151
MAXmalware (ai score=84)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTROJ_GEN.R002H0CFF22
RisingTrojan.FlyStudio!1.B596 (CLOUD)
YandexTrojan.GenAsa!WGWQpJ6T9wg
IkarusTrojan.Graftor
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FlyStudio.ONP!tr
BitDefenderThetaGen:NN.ZexaF.34742.8oNfaiIaqmgb
AVGWin32:Trojan-gen
Cybereasonmalicious.03151d

How to remove Win32/FlyStudio.ONP?

Win32/FlyStudio.ONP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment