Risk

RiskWare.Obfuscated.Python.Generic information

Malware Removal

The RiskWare.Obfuscated.Python.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.Obfuscated.Python.Generic virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine RiskWare.Obfuscated.Python.Generic?


File Info:

name: 8A331ADDC2FEC66A5D9C.mlw
path: /opt/CAPEv2/storage/binaries/762f5e75b59ca024d6cdd356c690e2ebe8f426b38b00b436bcd48d2b7e81004f
crc32: 55261A2A
md5: 8a331addc2fec66a5d9cd6e35cec3bc2
sha1: f1600612712fbdf4d7f351c04bf943ed1a4a2452
sha256: 762f5e75b59ca024d6cdd356c690e2ebe8f426b38b00b436bcd48d2b7e81004f
sha512: 8676e5171a6c7491c3c4122d6d451df03555344d9f7fc773fcb4675a49687a968b45c50a1efe758547db9fc850d1f9c63837d0395cd1b9caf2c80976bfeb58f7
ssdeep: 393216:uOu7L/DDFrDxpaUX47d45aWZ8yd/eo1V:uOCLP1LaUI7d45dZX1e
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1F7E633E4A3720EE5CC79C33AE6868E20F263B86507B4DACB439451671FA31D5B936F11
sha3_384: 5ffb3d8c19c3063024119cef0705a525a926d221beebf1164954c4c6060147c33c633da069ac420d2a01b50fa743fb84
ep_bytes: 4883ec28e8670200004883c428e97afe
timestamp: 2023-05-06 16:31:14

Version Info:

0: [No Data]

RiskWare.Obfuscated.Python.Generic also known as:

LionicTrojan.Win32.Shelm.tseF
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.33643921
FireEyeTrojan.Generic.33643921
ALYacTrojan.Generic.33643921
Cylanceunsafe
K7AntiVirusTrojan ( 005905411 )
AlibabaTrojanSpy:Win32/Obfuscated.6dd28d97
K7GWTrojan ( 005905411 )
ArcabitTrojan.Generic.D2015D91
CyrenW64/ABRisk.MQXD-1886
SymantecTrojan.Gen.MBT
ESET-NOD32Python/Spy.Agent.GN
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Python.Obfuscated.gen
BitDefenderTrojan.Generic.33643921
AvastFileRepMalware [Misc]
RisingSpyware.Agent/PYC!1.E350 (CLASSIC)
EmsisoftTrojan.Generic.33643921 (B)
F-SecureHeuristic.HEUR/AGEN.1319650
VIPRETrojan.Generic.33643921
McAfee-GW-EditionBehavesLike.Win64.Agent.tc
SophosMal/Generic-S
AviraHEUR/AGEN.1319650
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Python.Obfuscated.gen
GDataTrojan.Generic.33643921
GoogleDetected
McAfeeArtemis!8A331ADDC2FE
MAXmalware (ai score=82)
MalwarebytesRiskWare.Obfuscated.Python.Generic
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0AE623
TencentWin32.Trojan.Obfuscated.Oqil
FortinetW32/Agent.GN!tr.spy
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove RiskWare.Obfuscated.Python.Generic?

RiskWare.Obfuscated.Python.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment