Risk

About “RiskWare.Decrypter” infection

Malware Removal

The RiskWare.Decrypter is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.Decrypter virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine RiskWare.Decrypter?


File Info:

crc32: B430409B
md5: b1a1f206b1e7e264416b997c849dd3a1
name: upload_file
sha1: 850afb69800a4352f2f30c163d89c74dc2868c5f
sha256: d4fdf1950183893b509bea00c233ae5d54b87bdd57a0b90aa6bf27181ab108d4
sha512: 1328613761f6851760724c895d1daa8333962937b2d159ce319b1ffdd82f626383d5c0591048e55e8162382fc08d40d91f3e073a55ab9cc1df6e0c31194c4bc1
ssdeep: 1536:KCpa6mrgB+A7+fpIi6lmaptSiRkVICS4Arv:jIgWfpF6lmONlv
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

RiskWare.Decrypter also known as:

Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Sodinokibi-7013612-0
FireEyeGeneric.mg.b1a1f206b1e7e264
CAT-QuickHealRansom.Sodinokibi
McAfeeRDN/Ransom
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zusy.4!c
K7AntiVirusTrojan ( 0056cd1e1 )
BitDefenderGen:Variant.Fugrafa.10828
K7GWTrojan ( 0056cd1e1 )
Cybereasonmalicious.6b1e7e
InvinceaMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34216.hyW@a0YbjFf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.DJRI
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
CynetMalicious (score: 100)
AlibabaRansom:Win32/Sodinokibi.84bb9bab
ViRobotTrojan.Win32.Z.Zusy.121856.DZ
MicroWorld-eScanGen:Variant.Fugrafa.10828
RisingTrojan.Fuery!8.EAFB (TFE:5:LKgsnobeRzN)
Ad-AwareGen:Variant.Fugrafa.10828
ComodoTrojWare.Win32.Genome.ggltw@0
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.GenKryptik.Win32.54734
TrendMicroRansom_Sodinokibi.R06CC0DHN20
SophosMal/Generic-S
IkarusTrojan-Ransom.Sodinokibi
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftRansom:Win32/Sodinokibi.DSB!MTB
ArcabitTrojan.Fugrafa.D2A4C
GDataWin32.Trojan-Ransom.Sodinokibi.F
AhnLab-V3Malware/Win32.Generic.C3490719
Acronissuspicious
ALYacTrojan.Ransom.Sodinokibi
MAXmalware (ai score=99)
MalwarebytesRiskWare.Decrypter
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_Sodinokibi.R06CC0DHN20
TencentWin32.Trojan.Crypt.Pepd
SentinelOneDFI – Suspicious PE
FortinetW32/Graftor.2A43!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Ransom.f48

How to remove RiskWare.Decrypter?

RiskWare.Decrypter removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment