Risk

RiskTool.Win32.Agent.bjld removal

Malware Removal

The RiskTool.Win32.Agent.bjld is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.Agent.bjld virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)

How to determine RiskTool.Win32.Agent.bjld?


File Info:

name: AFA362980E9057375964.mlw
path: /opt/CAPEv2/storage/binaries/af080d53beb9fde833fc24545e49d46f40002692552851fdd9cd7e51260c00c7
crc32: CEFC0793
md5: afa362980e90573759646ccf0cbb9276
sha1: 36af4eaf49391e2ba6f4135c356126b5a53e819a
sha256: af080d53beb9fde833fc24545e49d46f40002692552851fdd9cd7e51260c00c7
sha512: 475ed0f25b19393329057bcf36c613d6061031b7d0775950f3340975ab72643adbe563e721d3604355710c2b0da643b43d9793d9a15ab80d66e77128b2c59321
ssdeep: 393216:2YfcwEWtkZWyfJSvaHde43LqyXKev2H7/G6ZoRl5LOID3k:yBUS04312HxoRb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8E633C371908872D2E12133159EDF71D238EA88AD77BB4BEA544F6FEAF1522C615603
sha3_384: 247684531554793e4e763c0e122e770c0603bebb323d251d0f8af9985328f185311b622cf2f6ff22828faef0680cfe54
ep_bytes: 558bec6aff68a86b4300687480410064
timestamp: 2012-07-13 04:29:17

Version Info:

Comments:
CompanyName: 杭州核新软件技术有限公司
FileDescription: 网上股票交易应用程序
FileVersion: 2019, 8, 31, 0
InternalName: E06
LegalCopyright: 版权所有(C) 2000,2011 核新软件
LegalTrademarks:
OriginalFilename: xiadan.exe
PrivateBuild:
ProductName: 网上交易主程序
ProductVersion: 5, 19, 15, 008
SpecialBuild: jrzdv1
Translation: 0x0804 0x04b0

RiskTool.Win32.Agent.bjld also known as:

LionicRiskware.Win32.Agent.1!c
MicroWorld-eScanTrojan.GenericKD.48830874
FireEyeGeneric.mg.afa362980e905737
ALYacTrojan.GenericKD.48830874
CylanceUnsafe
SangforRiskware.Win32.Agent.bjld
CyrenW32/Softcnapp.D.gen!Eldorado
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:RiskTool.Win32.Agent.bjld
BitDefenderTrojan.GenericKD.48830874
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.48830874
EmsisoftTrojan.GenericKD.48830874 (B)
ZillyaTrojan.Agent.Win32.1220623
TrendMicroTROJ_GEN.R002C0WDC22
Trapminesuspicious.low.ml.score
GDataTrojan.GenericKD.48830874
AviraTR/Spy.Banker.keiwu
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!AFA362980E90
TACHYONBanker/W32.Agent.15138816
VBA32Trojan.MulDrop
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002C0WDC22
RisingTrojan.Zpevdo!8.F912 (CLOUD)
IkarusTrojan.Win32
MaxSecureTrojan.Malware.177253946.susgen
FortinetW32/Agent.APFH!tr
AVGWin32:Malware-gen

How to remove RiskTool.Win32.Agent.bjld?

RiskTool.Win32.Agent.bjld removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment