Risk

RiskWare.SMSBomber removal guide

Malware Removal

The RiskWare.SMSBomber is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.SMSBomber virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine RiskWare.SMSBomber?


File Info:

crc32: 4EE7B04F
md5: d81221f45a8cfc2d65abbe34497347d4
name: qqzfzs.exe
sha1: b5b7909382c616934caa28bab4b6393ad7752420
sha256: 0b512f2d0289229c990469d849e9fc12792ccf790342def80863595c364f8897
sha512: 4d30bcd4cc717ff0f1aea91e8305883a2a01e3ff14186d0d02a4789fda9e20e09569f34f8ebafd71b7d4a50f857b251f5b95dfcb3e134d611abe9ce110ddcb08
ssdeep: 98304:IkxmxS4nQml4g9TwAld/9y970EKxBT16d6Osxx3:I1S0bl4gmQ9y97zKxKdex3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

RiskWare.SMSBomber also known as:

MicroWorld-eScanGen:Variant.Razy.342883
CAT-QuickHealTrojan.Dynamer
McAfeeArtemis!D81221F45A8C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00563cb01 )
BitDefenderGen:Variant.Razy.342883
K7GWTrojan ( 00563cb01 )
Cybereasonmalicious.45a8cf
TrendMicroTROJ_FRS.VSN13C18
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Application.Agent.EPOLEY
AlibabaPacked:Win32/VMProtect.99206cc4
NANO-AntivirusTrojan.Win32.Razy.fnafvq
AegisLabTrojan.Win32.Malicious.4!e
RisingTrojan.Dynamer!8.3A0 (CLOUD)
SophosMal/VMProtBad-A
ComodoMalware@#77dmo2kkh877
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.wc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d81221f45a8cfc2d
EmsisoftGen:Variant.Razy.342883 (B)
CyrenW32/MSIL_Kryptik.AQR.gen!Eldorado
Antiy-AVLTrojan/Win32.Dynamer
ArcabitTrojan.Razy.D53B63
MicrosoftTrojan:Win32/Dynamer!rfn
MAXmalware (ai score=88)
MalwarebytesRiskWare.SMSBomber
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.VMProtect.ACF
TrendMicro-HouseCallTROJ_FRS.VSN13C18
IkarusTrojan.Win32.VMProtect
FortinetW32/SMSBomber.A!tr
BitDefenderThetaGen:NN.ZemsilF.34108.@t0@aip9EHh
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove RiskWare.SMSBomber?

RiskWare.SMSBomber removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment