Spy

Win32/Spy.FlyStudio.NAH malicious file

Malware Removal

The Win32/Spy.FlyStudio.NAH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.FlyStudio.NAH virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Spy.FlyStudio.NAH?


File Info:

name: 05763B141A9AE7B3AFDB.mlw
path: /opt/CAPEv2/storage/binaries/811930a1d96cc9f1713025821081931c07da982b2a222775cb90910b28f1da60
crc32: 75F8C6FC
md5: 05763b141a9ae7b3afdb848e8d9cf5d0
sha1: 55a004f3afee51ca7b66fb553c1aa3c15f8dcee0
sha256: 811930a1d96cc9f1713025821081931c07da982b2a222775cb90910b28f1da60
sha512: 32713187f4571c1ebe30458936972355b2d93598ab5aa5375427678ab5323a55f7902e24ecf5a9f0f7d65956b3e9738e1d151ab881adf60a3876adfbce9bf4d0
ssdeep: 24576:2ivNm32FNsuNas4EYXfu2/zNmp1SHbm7mCmCX0WIwl:243HYVoeHbm7mCmg0k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B656B23A00284A2D5551AB039FB1F79EDB857B10D31DD87E7E4EDB92E32671CA2B01D
sha3_384: 45f28e7329e1cd984e1bdf11a47a09d238098c79271be974ade6445926de660695a4dac75052532765a5104a832706ac
ep_bytes: 558bec6aff6870e95000688cec4c0064
timestamp: 2013-04-28 20:28:14

Version Info:

0: [No Data]

Win32/Spy.FlyStudio.NAH also known as:

BkavW32.AIDetectMalware
SkyhighBehavesLike.Win32.Generic.tm
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.3afee5
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.FlyStudio.NAH
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.AVKill.czgiun
AvastWin32:TrojanX-gen [Trj]
F-SecureTrojan:W32/DelfInject.R
DrWebTrojan.AVKill.30900
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.05763b141a9ae7b3
SentinelOneStatic AI – Malicious PE
JiangminHeur:TrojanSpy/Banker
GoogleDetected
AviraHEUR/AGEN.1340846
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1CJUYU
VaristW32/Trojan.CLL.gen!Eldorado
BitDefenderThetaGen:NN.ZexaF.36792.DrZ@aa8wBRe
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
RisingStealer.OnlinePay!1.657A (CLASSIC)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FlyApplication
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Spy.FlyStudio.NAH?

Win32/Spy.FlyStudio.NAH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment