Risk

RiskWare.MonitoringTool removal

Malware Removal

The RiskWare.MonitoringTool is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.MonitoringTool virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system

Related domains:

wpad.local-net
certificates.godaddy.com
charm.bizfxr.com

How to determine RiskWare.MonitoringTool?


File Info:

name: B6D8BF9E3F8B0E465068.mlw
path: /opt/CAPEv2/storage/binaries/1f796cccec02f6eaf63e089d5e96931eccc718aa988f8a8c18ec610e42760153
crc32: 279C5DC9
md5: b6d8bf9e3f8b0e465068a5946d961c02
sha1: ec48f2b2edb370ccf46a65caaf1e42e87ecacb08
sha256: 1f796cccec02f6eaf63e089d5e96931eccc718aa988f8a8c18ec610e42760153
sha512: dd405b837f5ab9da11f48e46092f00bf960e090350accc0893bc4471a21f2559984b1f2c437d8202acb2f74f17d83a2e42bfa7aabd0e914d974d41e65c9f83ff
ssdeep: 6144:Zsgk6cLSmKUi4/83ZtXBYvZ6rrtoDxDm5Vf8NE5vu/tAQZJIiwpxB+lixrZ2xF67:ZstSmhYLH0EIJBwp3EFnOi59gX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16BE4733EB391B23DF422C0B07A1863B940EC783905ADB45AF3829B1976F49D6F525B17
sha3_384: bef80926f0598d8ed3e131a8ec1b7a4ef2cf4b85d740b34aae3360d95b97d76a3b4a3936423d3181ecf4f8f56e6b02ea
ep_bytes: 68a8764000e8f0ffffff000000000000
timestamp: 2018-07-19 16:55:12

Version Info:

Translation: 0x0409 0x04b0
CompanyName: AMTGI
ProductName: AMTGi_ClientMonitoring
FileVersion: 1.09.0734
ProductVersion: 1.09.0734
InternalName: CHARM
OriginalFilename: CHARM.exe

RiskWare.MonitoringTool also known as:

LionicTrojan.Win32.Sharm.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46984660
FireEyeGeneric.mg.b6d8bf9e3f8b0e46
McAfeeGenericRXAA-AA!B6D8BF9E3F8B
CylanceUnsafe
SangforSpyware.Win32.Sharm.bp
ESET-NOD32a variant of Win32/Monitor.AMTGiMon.B potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CIG21
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Sharm.bp
BitDefenderTrojan.GenericKD.46984660
NANO-AntivirusTrojan.Win32.Sharm.fisttk
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.46984660
SophosGeneric PUA OM (PUA)
ComodoMalware@#26p1z2q857e1o
ZillyaDropper.Monitor.Win32.37
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.46984660 (B)
JiangminTrojanSpy.Sharm.aq
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.27170DB
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.46984660
CynetMalicious (score: 99)
AhnLab-V3Spyware/Win32.Sharm.R217614
VBA32TScope.Trojan.VB
ALYacTrojan.GenericKD.46984660
MalwarebytesRiskWare.MonitoringTool
APEXMalicious
TencentWin32.Trojan-spy.Sharm.Phqe
YandexTrojan.GenAsa!mqQtNVe//IE
FortinetW32/Sharm.BP!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove RiskWare.MonitoringTool?

RiskWare.MonitoringTool removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment