Risk

Should I remove “RiskWare.Agent.UPX”?

Malware Removal

The RiskWare.Agent.UPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.Agent.UPX virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine RiskWare.Agent.UPX?


File Info:

name: 2A25534921E773B05B63.mlw
path: /opt/CAPEv2/storage/binaries/4d3b12c5cc96aa342865d2efda137cd627a8d2c44c13e14b38fa3d8fad468d48
crc32: C429A58E
md5: 2a25534921e773b05b632a4280ab7e7b
sha1: e54679d3ae9f8bb5e562f8bce1df84c025c1994a
sha256: 4d3b12c5cc96aa342865d2efda137cd627a8d2c44c13e14b38fa3d8fad468d48
sha512: 44f434d92e047ab996d9e55498db15d414d55e0da4ccb594aa2497456aa4603dd102d6166d88a836f456d85c1f5fc0047e7411c3ce8eb58936ad825e169cc904
ssdeep: 192:UnuDXuFkSoVlViw6AWwj9iNxyVt/GM/4YiJtaivu:U76lVikW0Bt/zAYiyivu
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T132029E2413700ED9CB2B0B7DACC7A7AC23B5B375178F9B1C7F1598DA23844496DC1515
sha3_384: 553bf8859b7c83c2d009bdbca3754857c2f9e1759d408ca1785321c620843e7e462de8caf4dd991b3e1731d943e87cad
ep_bytes: 53565755488d3515edffff488dbe00a0
timestamp: 2021-11-30 08:15:39

Version Info:

0: [No Data]

RiskWare.Agent.UPX also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGeneric.Exploit.Shellcode.2.0A9EB0FB
FireEyeGeneric.Exploit.Shellcode.2.0A9EB0FB
ALYacGeneric.Exploit.Shellcode.2.0A9EB0FB
MalwarebytesRiskWare.Agent.UPX
AlibabaTrojan:Win64/Meterpreter.45f909aa
Cybereasonmalicious.921e77
SymantecMeterpreter
ESET-NOD32a variant of Win64/Rozena.BY
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Exploit.Shellcode.2.0A9EB0FB
AvastWin64:Trojan-gen
TencentWin32.Trojan.Generic.Hqlp
Ad-AwareGeneric.Exploit.Shellcode.2.0A9EB0FB
EmsisoftGeneric.Exploit.Shellcode.2.0A9EB0FB (B)
TrendMicroTrojan.Win64.SHELMA.SMB1
McAfee-GW-EditionBehavesLike.Win64.Generic.xh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Rozena.zaxdx
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win64/Meterpreter.E
GDataGeneric.Exploit.Shellcode.2.0A9EB0FB
CynetMalicious (score: 100)
McAfeeArtemis!2A25534921E7
MAXmalware (ai score=81)
CylanceUnsafe
RisingTrojan.Agent!1.C856 (CLASSIC)
IkarusPUA.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Rozena
AVGWin64:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove RiskWare.Agent.UPX?

RiskWare.Agent.UPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment