Trojan

Should I remove “Trojan:Win32/Risepro.RPX!MTB”?

Malware Removal

The Trojan:Win32/Risepro.RPX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Risepro.RPX!MTB virus can do?

  • Unconventionial binary language: Romanian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Risepro.RPX!MTB?


File Info:

name: B464437E09EABBCD0D22.mlw
path: /opt/CAPEv2/storage/binaries/100496b46f95f1400deb71deb6a706262401a2a9f7f6c56d30eb37297bacac88
crc32: FFF84565
md5: b464437e09eabbcd0d22dd7e2f024dda
sha1: 073527bae8f496e95446d549787bc94c56c6b30f
sha256: 100496b46f95f1400deb71deb6a706262401a2a9f7f6c56d30eb37297bacac88
sha512: 1f048be8ea0b44462e7bbe069e4d61eaf400c88f0dedd586d51c45a7e0d2dd6e2a5b2af0904efccae2e8b5f87f731a73a23892f7f4a5c0a6248aa0324a48fe92
ssdeep: 196608:aoWn4eH5sA9D3FATSndxPB2Dt8aS9YGuDcFMzfhAsrERS7TDh:xtChSTSdxp2GaSuGozfxco
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E59623C164CA90F8EAC05F70D65766CB17B5456B8EC88924ABC13C06A4D5FB271BACF3
sha3_384: 8768785e5196a6248c80cba1aaa8f5e2ee066f70356b021b6ec4e6a91f1340d457e9cab10140145181aec6654ddfff3a
ep_bytes: e8c9421900660fb6840ab2fec9d4660f
timestamp: 2023-08-10 18:12:21

Version Info:

CompanyName: Microsoft
FileDescription: Microsoft Office Installer
FileVersion: 1.0.0.1
InternalName: Office.exe
LegalCopyright: Copyright (C) 2022
OriginalFilename: Office.exe
ProductName: Office
ProductVersion: 1.0.0.1
Translation: 0x0418 0x04b0

Trojan:Win32/Risepro.RPX!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.RisePro.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.32636
MicroWorld-eScanGen:Variant.Lazy.373316
FireEyeGeneric.mg.b464437e09eabbcd
SkyhighBehavesLike.Win32.Generic.rc
McAfeeArtemis!B464437E09EA
MalwarebytesSpyware.PasswordStealer
ZillyaTrojan.VMProtect.Win32.90692
SangforInfostealer.Win32.Risepro.Vzra
K7AntiVirusTrojan ( 0059f0a91 )
K7GWTrojan ( 0059f0a91 )
Cybereasonmalicious.e09eab
BitDefenderThetaGen:NN.ZexaF.36802.@F0@a4Hes6hk
VirITTrojan.Win32.Genus.SSK
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.VMProtect.BB suspicious
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DBF24
KasperskyTrojan-PSW.Win32.RisePro.aa
BitDefenderGen:Variant.Lazy.373316
NANO-AntivirusTrojan.Win32.RisePro.jylvkg
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.13ec3043
EmsisoftGen:Variant.Lazy.373316 (B)
F-SecureTrojan.TR/Redcap.ggbwn
VIPREGen:Variant.Lazy.373316
TrendMicroTROJ_GEN.R002C0DBF24
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
GoogleDetected
AviraTR/Redcap.ggbwn
VaristW32/ABRisk.ARUK-2152
Antiy-AVLTrojan[Packed]/Win32.VMProtect
KingsoftWin32.Troj.Generic.v
MicrosoftTrojan:Win32/Risepro.RPX!MTB
XcitiumMalware@#3j3mismsl3afw
ArcabitTrojan.Lazy.D5B244
ZoneAlarmTrojan-PSW.Win32.RisePro.aa
GDataGen:Variant.Lazy.373316
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Evo-gen.C5469531
VBA32TrojanPSW.RisePro
ALYacGen:Variant.Lazy.373316
Cylanceunsafe
PandaTrj/Chgt.AD
RisingTrojan.Generic@AI.100 (RDML:biEn6OE6G5XN5XGbmuZ+JA)
YandexTrojan.PWS.RisePro!QfHxM/K4Cuk
MaxSecureTrojan.Malware.1728101.susgen
FortinetRiskware/Application
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[stealer]:Win/RisePro.aa

How to remove Trojan:Win32/Risepro.RPX!MTB?

Trojan:Win32/Risepro.RPX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment