How it Workse
Win32/FlyStudio creates a sub-folder named 306a39 or dd33d3 or de08b0 inside the windows\system32 folder and copies several files with the following names; com.run, internet.fne, dp1.fne, krnln.fnr, eapi.fne, 00c3ac.exe, 394d.edt, etc.
Apart from copying itself in the windows\system32 folder it deletes some of the files present in user_profile\local settings\temporary internet files\content.ie5 folder.
It also does some registry changes like adding a new entry or modifying the existing entry in the system registry. It modifies the following registry entries.
%path1% = hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\windows\currentversion\explorer\mountpoints2
%path1%\a\ : baseclass =drive
%path1%\c\ : baseclass =drive
%path1%\d\ : baseclass =drive
%path1%\e\ : baseclass =drive