Risk

RiskWare.AVDis.MSIL (file analysis)

Malware Removal

The RiskWare.AVDis.MSIL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.AVDis.MSIL virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine RiskWare.AVDis.MSIL?


File Info:

crc32: 37EB72CC
md5: b7352a9cde99367d4053d0de7431a181
name: 1.exe
sha1: 32d2046f588a98c1ea0fee63d1c275b34497ddea
sha256: 9dd0d5b5b5efe2433cfcbc3044d0219ffeb517c2cde4e705e52719ed15660a00
sha512: 8b6cee0cdd86c616e6a5e65bb08ad9df2926b5fa16b7186166e6fb69ca8eb3f1cef98f3e03ab2ae43c082b6acae82edd0a45d71df14b504ae7bf82da049796df
ssdeep: 1536:QPzUmdx2gahvwPBW7rfoOcwCJpPYnlbobN8+DF:QPzUQ2gyYqrf5cwipKlbob62
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright:
FileVersion: 7.0.0.0
FileDescription: csrss
Translation: 0x0409 0x0000

RiskWare.AVDis.MSIL also known as:

MicroWorld-eScanTrojan.GenericKD.32672295
FireEyeGeneric.mg.b7352a9cde99367d
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.32672295
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1098990
SangforMalware
K7AntiVirusTrojan ( 0051ed981 )
AlibabaTrojan:BAT/KillAV.4470b106
K7GWTrojan ( 0051ed981 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Generic.D1F28A27
Invinceaheuristic
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.GenericKD.32672295
NANO-AntivirusTrojan.Win32.KillAV.fqefzy
AegisLabTrojan.MSIL.Agent.4!c
RisingTrojan.Agent!8.B1E (CLOUD)
Ad-AwareTrojan.GenericKD.32672295
SophosMal/Generic-S
ComodoMalware@#3sbua5ahnjbrx
F-SecureTrojan.TR/Agent.wqbpm
DrWebTrojan.FakeAV.20338
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R047C0DAS20
McAfee-GW-EditionBehavesLike.Win32.AdwareDotDo.qh
Trapminemalicious.moderate.ml.score
CMCTrojan.Win32.Miner!O
EmsisoftTrojan.GenericKD.32672295 (B)
IkarusTrojan.Agent
CyrenW32/Trojan.ODEZ-0351
WebrootTrojanspy:Win32/Mafod!rts
AviraTR/Agent.wqbpm
Antiy-AVLTrojan/MSIL.Agent
MicrosoftPUA:Win32/RelevantKnowledge
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agent.gen
GDataTrojan.GenericKD.32672295
McAfeeArtemis!B7352A9CDE99
MAXmalware (ai score=94)
VBA32Trojan.MSIL.Agent
MalwarebytesRiskWare.AVDis.MSIL
PandaTrj/CI.A
ESET-NOD32NSIS/TrojanDropper.Agent.CQ
TrendMicro-HouseCallTROJ_GEN.R047C0DAS20
TencentMsil.Trojan.Agent.Pefl
YandexTrojan.Agent!fxct73TQh/c
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.8703358.susgen
FortinetW32/Agent.CQ!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.cde993
AvastWin32:TrojanX-gen [Trj]
Qihoo-360Generic/Trojan.289

How to remove RiskWare.AVDis.MSIL?

RiskWare.AVDis.MSIL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment