Risk

RiskWare.PasswordStealer.Discord malicious file

Malware Removal

The RiskWare.PasswordStealer.Discord is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.PasswordStealer.Discord virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine RiskWare.PasswordStealer.Discord?


File Info:

name: B16C720B52AD85CF1906.mlw
path: /opt/CAPEv2/storage/binaries/c2d986774a3802a87c987914bf0284a88f209a4cd093834b531b148560705227
crc32: 4AB0B883
md5: b16c720b52ad85cf1906c03616f5ae85
sha1: 4a77151a5e48e49f8916ac5bccb841fe1d811364
sha256: c2d986774a3802a87c987914bf0284a88f209a4cd093834b531b148560705227
sha512: ab87aaae7be88f1e78f6be471b0985ef0a9012fcc0c50ecd5b0c55effcdf86b6b98a14c4d9edf0d20055f10060d4cb4b90d819653b3acc1146884c9307e7ef9e
ssdeep: 12288:7DbZ8lYMomK36i3Ufjd3YIAX6ZQs2XiOu3U3Qn0BrAYMthRiCQLrYlAB2:IomKqE9X6ZQ3XXQ0BrADl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2351752B7B9CA53E29E1733D4E4D93887A0EC51D6A6E70F21D52EAB3C033A78D04356
sha3_384: 91fff2c20e3affe47b8155f8be8af3cad6628bc9dd3e7e2e80937b7b65b78d6915a94c1e69754dc24c527610ee005eda
ep_bytes: ff250020400000000000000000000000
timestamp: 2062-05-19 21:15:31

Version Info:

Translation: 0x0000 0x04b0
Comments: The beta version of the injector
CompanyName: TRXSH
FileDescription: TRXSHWare Injector
FileVersion: 1.0.0
InternalName: TrxshWareInjector.exe
LegalCopyright: 2022
LegalTrademarks:
OriginalFilename: TrxshWareInjector.exe
ProductName: TRXSHWare
ProductVersion: 1.0.0
Assembly Version: 1.0.0.0

RiskWare.PasswordStealer.Discord also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Disco.i!c
Elasticmalicious (moderate confidence)
DrWebTrojan.PWS.DiscordNET.48
MicroWorld-eScanTrojan.GenericKD.61272706
FireEyeTrojan.GenericKD.61272706
McAfeeGenericRXUA-LF!B16C720B52AD
CylanceUnsafe
ZillyaTrojan.Stealer.Win32.27189
SangforInfostealer.Win32.Agent.V3oq
AlibabaTrojanPSW:MSIL/Stealer.0c45bbd6
CyrenW32/ABRisk.BWVF-4824
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WHF22
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderTrojan.GenericKD.61272706
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-QQPass.QQRob.Wylw
Ad-AwareTrojan.GenericKD.61272706
EmsisoftTrojan.GenericKD.61272706 (B)
VIPRETrojan.GenericKD.61272706
TrendMicroTROJ_GEN.R002C0WHF22
McAfee-GW-EditionGenericRXUA-LF!B16C720B52AD
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraTR/Redcap.ywuyn
Antiy-AVLTrojan/Generic.ASMalwS.6EF0
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataMSIL.Trojan-Stealer.DiscordStealer.D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R512052
VBA32Downloader.MSIL.gen.rexp
MAXmalware (ai score=86)
MalwarebytesRiskWare.PasswordStealer.Discord
APEXMalicious
RisingStealer.Discord!8.10A86 (CLOUD)
MaxSecureTrojan.Malware.74396735.susgen
FortinetPossibleThreat
AVGWin32:PWSX-gen [Trj]
PandaTrj/Chgt.AD

How to remove RiskWare.PasswordStealer.Discord?

RiskWare.PasswordStealer.Discord removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment