Risk

Win32/RiskWare.2345.I information

Malware Removal

The Win32/RiskWare.2345.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RiskWare.2345.I virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/RiskWare.2345.I?


File Info:

name: 6BBCA6D18B99FECF46D4.mlw
path: /opt/CAPEv2/storage/binaries/40d58dcc667f6bf9df6b953477ce4242a8f89a89ebc3fe9430cdf828271fad5b
crc32: D4CD65BF
md5: 6bbca6d18b99fecf46d4f689b56f23a6
sha1: 47b9055537adf2a6bcee91d07ad657bc4203e0dd
sha256: 40d58dcc667f6bf9df6b953477ce4242a8f89a89ebc3fe9430cdf828271fad5b
sha512: 51ab9a0b8781f714656f893587e3a7739240b71d43e30aa6ad73abd911eb6d628dd1922dbc0bf3086e41cb9a1758eb2e91d8c82334c862e66dc5cb6aa304e2a9
ssdeep: 24576:VII2mRVMuLi/mDnICLJ4gxqBe57/ATDNoo3cK0Ef2gsOv:wmRV247qBe57/ATDNo2+Ef2gsOv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3457C04FB43D2BDCE6201B02667FB1A507879859B296ED3D7D43F0A0531AC2BA3B55D
sha3_384: 43c11fa58b5b080e620aec571d2779748224b306461726609a2b93ceb9ff898bc92cb4f705f961007dd424eb490920b7
ep_bytes: e8f7ac0000e97ffeffff558bec568bf1
timestamp: 2020-04-15 07:01:22

Version Info:

Comments: 2345.com
CompanyName: 2345移动科技
FileDescription: 2345辅助模块
FileVersion: 4.3.3.1543
InternalName: Helper_2345
LegalCopyright: 版权所有 (C) 2020, 2345移动科技
OriginalFilename: Helper_2345.exe
ProductName: 2345辅助模块
ProductVersion: 4.3.3.1543
Translation: 0x0804 0x04b0

Win32/RiskWare.2345.I also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.MiniPage.2!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.6bbca6d18b99fecf
CAT-QuickHealTrojan.GenericRI.S24292251
CylanceUnsafe
ZillyaTool.2345.Win32.536
SangforVirus_Suspicious.Win32.Sality.bh
K7AntiVirusRiskware ( 0057243a1 )
AlibabaAdWare:Win32/MiniPage.b59d3e7c
K7GWRiskware ( 0057243a1 )
Cybereasonmalicious.537adf
BitDefenderThetaGen:NN.ZexaF.34062.lv2@aCDXIPoi
CyrenW32/Sality.BB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.2345.I
TrendMicro-HouseCallPE_SALITY.ER
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.MiniPage.gen
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Sality [Inf]
TencentWin32.Adware.Minipage.Wsau
VIPREVirus.Win32.Sality.atbh (v)
TrendMicroPE_SALITY.ER
McAfee-GW-EditionBehavesLike.Win32.PUP.th
SophosGeneric PUA EH (PUA)
IkarusPUA.RiskWare
AviraTR/Patched.Ren.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32Adware.Ad
APEXMalicious
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpr7+JfvdUc02u1eF/P4I6D)
SentinelOneStatic AI – Malicious PE
FortinetRiskware/2345
AVGWin32:Sality [Inf]

How to remove Win32/RiskWare.2345.I?

Win32/RiskWare.2345.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment