Risk

RiskWare.Packed.ZProtect removal instruction

Malware Removal

The RiskWare.Packed.ZProtect is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.Packed.ZProtect virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine RiskWare.Packed.ZProtect?


File Info:

crc32: 081D4BF8
md5: 89f66bcc4226f3d1bb0c35d5c7abcbf6
name: xk5hcywcwo84jfezchj7rwsq2xo96rcy.exe
sha1: b0d317de232034d1dc5d9c53337f11a9e7134b12
sha256: 4f03797d705a7eeeaa982ba453fb7ee10cede62fd67442a7f0290edc24cbea57
sha512: 316d86848ba8bf1eb3b279fa0d336deda5ea0b706b15bc304ca1523f6dd06730b309f3aeb2187d297851b4987a7b6166d089d48178888d74310df4cb3ac33b10
ssdeep: 24576:+P9/FUgR3PuzQux7DPEOqL2PsGSfa2sWYnctqbWBX8i2TB8R:IcCmzQEsOQLfa2GnWT8i2N8R
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

RiskWare.Packed.ZProtect also known as:

MicroWorld-eScanTrojan.GenericKD.32932092
FireEyeGeneric.mg.89f66bcc4226f3d1
CAT-QuickHealTrojan.Generic
Qihoo-360Generic/HEUR/QVM18.1.800B.Malware.Gen
McAfeeBackDoor-EXZ
CylanceUnsafe
VIPRETrojan-Dropper.Win32.Resdro.b (v) (not malicious)
SangforMalware
K7AntiVirusTrojan ( 001e15121 )
BitDefenderTrojan.GenericKD.32932092
K7GWTrojan ( 001e15121 )
Cybereasonmalicious.e23203
TrendMicroTROJ_GEN.R002C0PAB20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.32932092
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Click3.gueqdg
ViRobotTrojan.Win32.Z.Zegost.966656
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareTrojan.GenericKD.32932092
SophosMal/EncPk-ANJ
F-SecurePacked:W32/PeCan.A
DrWebTrojan.Click3.11121
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Sdbot.dc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.32932092 (B)
IkarusBackdoor.Win32.Zegost
CyrenW32/Trojan.ZVKT-2415
JiangminTrojan.Generic.ekuac
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F680FC
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.D!ml
Acronissuspicious
VBA32BScope.Trojan.WinSpy
ALYacTrojan.GenericKD.32932092
MalwarebytesRiskWare.Packed.ZProtect
PandaTrj/CI.A
ESET-NOD32a variant of Win32/FlyStudio.Packed.V potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PAB20
TencentWin32.Trojan.Generic.Eerm
YandexTrojan.Agent!lIjo+dRxZzo
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Generic
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove RiskWare.Packed.ZProtect?

RiskWare.Packed.ZProtect removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment