Risk

How to remove “RiskWare.Packed.BlackMoon”?

Malware Removal

The RiskWare.Packed.BlackMoon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.Packed.BlackMoon virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine RiskWare.Packed.BlackMoon?


File Info:

crc32: C3211AB8
md5: 0816516d7bddf647bbae49e00bc62e0b
name: abuiabblgaagovqp6wuo3oj90ai
sha1: 4b2027f430a682631f9bd6e985110ab6ccbdf110
sha256: 2ffd8b7673a954803e2db3e5f1632aae514f56d945881d4f9fb96b109c88f08e
sha512: 99287f71854d5e1a8179b72f3d58e6b7ceb695d851fdeeb1aad50168aeb8956d9aae7b63653b3c842b4c68ac2bfbc9c89063204a4b373d98dac3f7d019b3fb15
ssdeep: 6144:w38DtiN3/WXKPMFakVhOm+lpQDkLVpIJV0rzXVq3D68Yi0MkG4jNzuVIvprHT:wYE3/c4wakHT+lpQDkLVpIX0nXVq3D6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

RiskWare.Packed.BlackMoon also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanDropped:Trojan.GenericKD.32369243
FireEyeGeneric.mg.0816516d7bddf647
CAT-QuickHealTrojan.Generic.2919
Qihoo-360Win32/Trojan.031
ALYacDropped:Trojan.GenericKD.32369243
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderDropped:Trojan.GenericKD.32369243
Cybereasonmalicious.d7bddf
BitDefenderThetaGen:NN.ZexaF.34090.wmW@aeX43nb
CyrenW32/Trojan.XUZB-3426
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
GDataWin32.Trojan.Agent.WP
KasperskyTrojan.Win32.Blamon.kar
AlibabaTrojanDownloader:Win32/Blamon.d6680c43
NANO-AntivirusVirus.Win32.Gen.ccmw
AegisLabTrojan.Win32.Blamon.4!c
APEXMalicious
TencentWin32.Trojan.Blamon.Dkw
Ad-AwareDropped:Trojan.GenericKD.32369243
SophosMal/Packer
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.Siggen7.35352
ZillyaTrojan.Tiny.Win32.7552
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Pykse.fh
Trapminemalicious.high.ml.score
EmsisoftDropped:Trojan.GenericKD.32369243 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/BlackMoon.J.gen!Eldorado
AviraTR/Spy.Gen
Antiy-AVLTrojan/Win32.Blamon
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1EDEA5B
ZoneAlarmTrojan.Win32.Blamon.kar
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Blamon.C3456260
Acronissuspicious
McAfeeGenericRXEE-SE!0816516D7BDD
MAXmalware (ai score=83)
VBA32BScope.Trojan.Miner
MalwarebytesRiskWare.Packed.BlackMoon
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
RisingTrojan.Kryptik!1.B3E8 (CLASSIC)
YandexTrojan.Blamon!
IkarusPUA.BlackMoon
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.BBYK!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.74538225.susgen

How to remove RiskWare.Packed.BlackMoon?

RiskWare.Packed.BlackMoon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment