Risk

Win32/RiskWare.SmartBrowser.A malicious file

Malware Removal

The Win32/RiskWare.SmartBrowser.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RiskWare.SmartBrowser.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Attempts to masquerade or mimic a legitimate process or file name
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/RiskWare.SmartBrowser.A?


File Info:

name: 751925474DD193189197.mlw
path: /opt/CAPEv2/storage/binaries/9c9bb2ca5aed10d6fdce32f99a29e214bb9f38883aca8972e300469389bf24e2
crc32: DC5541FC
md5: 751925474dd193189197f55d6a105358
sha1: e8f4a801cdeeb0a111da638bfe91791143fbe818
sha256: 9c9bb2ca5aed10d6fdce32f99a29e214bb9f38883aca8972e300469389bf24e2
sha512: 25d8ba403d9a186975cca766a9e5285cd5f18b8e4f1302aaab1d66ffb98f98985ac941bed9faf63e3ac9aa72b84251ec34b341e7a90ddff243ca3ce2ea7ee429
ssdeep: 6144:Z1ontzdiGQMRSn8s+TgYToXjIJcY6sNztXSvRTODwj6fQEpYjOdszAQ1uPwLC:LoBdE4s+TrvcYRtXSvQDwGoZjUszAQNm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA8402C4F291F1BBD5AA82F18772D939A3667C2844390E3B779C7F6668352071139E23
sha3_384: 342ed626c971270e7b132cfdd77de080da7657a9f258675ab9e56c42af7fd1d2a59a10851e614dea17ea997f14f4a5de
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-12-11 21:50:45

Version Info:

0: [No Data]

Win32/RiskWare.SmartBrowser.A also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.SmartBroex.1
MicroWorld-eScanTrojan.GenericKD.47531405
FireEyeGeneric.mg.751925474dd19318
ALYacApplication.Agent.JAS
CylanceUnsafe
SangforPUP.Win32.Agent.JAS
K7AntiVirusRiskware ( 0057f7871 )
AlibabaAdWare:Win32/SmartBrowser.f5cc436d
K7GWRiskware ( 0057f7871 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZedlaF.34062.fu4@aqQGOIli
ESET-NOD32Win32/RiskWare.SmartBrowser.A
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Agent.xxypph
BitDefenderTrojan.GenericKD.47531405
NANO-AntivirusRiskware.Win32.SmartBroex.fslpbz
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.47531405 (B)
ComodoApplicUnwnt@#t67z1wg4he29
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Browser.fc
SophosGeneric PUA OI (PUA)
AviraHEUR/AGEN.1116914
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2D5458D
GDataApplication.Agent.JAS
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.R288475
McAfeeArtemis!751925474DD1
VBA32BScope.Trojan.MSIL.Inject
TrendMicro-HouseCallTROJ_GEN.R002H0CL121
YandexTrojan.GenAsa!LspPmGb+gHs
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/Agent
AVGWin32:Malware-gen
Cybereasonmalicious.74dd19
PandaTrj/CI.A

How to remove Win32/RiskWare.SmartBrowser.A?

Win32/RiskWare.SmartBrowser.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment