Risk

About “Risktool.Generic.21436” infection

Malware Removal

The Risktool.Generic.21436 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Risktool.Generic.21436 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Risktool.Generic.21436?


File Info:

name: 277E660F75342C826FC2.mlw
path: /opt/CAPEv2/storage/binaries/066a7717c8a8d155e8459ecb12ca2ad82c7cee07707a423d340723b6a628b2b3
crc32: A5A6E520
md5: 277e660f75342c826fc222f5a93650ca
sha1: 17d29ba9310136a4e5350778f233aa5e3db443f0
sha256: 066a7717c8a8d155e8459ecb12ca2ad82c7cee07707a423d340723b6a628b2b3
sha512: e54b7dcdfc45618a5587e4bcbb9bb98c3da542c0568b8e049916071b7c1223e63996324d2f9b8f0663acaa40fc75dc523909f176b76c0b2c64aebf80a0b9b998
ssdeep: 98304:Mkio0pvEvSS725SbWf+YFCNv3tLkoJOWd0G2MYeFgr+zJyXhS6QrRhLBUSiWlRCG:Mkio0pvEvSS72Qaf+HNv3tHJOWd6M7g/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA469D13B3E6E023D0635170197A73BDA6B8BDFD6C25A90B6340BA5C2D31BC1E62571B
sha3_384: a733e2a8a1b0b9fb60af09acc382728cd395bd1a445fae0a5c9759649fdb5cb8127c732a48263b46959c119ae30a62c2
ep_bytes: 6858234000e8eeffffff000000000000
timestamp: 2013-05-11 13:54:34

Version Info:

Translation: 0x0804 0x04b0
CompanyName: Microsoft Corporation
ProductName: 大芒果
FileVersion: 1.08.0006
ProductVersion: 1.08.0006
InternalName: 斩仙大芒果
OriginalFilename: 斩仙大芒果.exe

Risktool.Generic.21436 also known as:

BkavW32.Common.D867AD69
LionicRiskware.Win32.IMEStartup.1!c
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.277e660f75342c82
CAT-QuickHealRisktool.Generic.21436
SkyhighBehavesLike.Win32.Fujacks.th
AlibabaRiskWare:Win32/IMEStartup.27af5ff6
Cybereasonmalicious.931013
APEXMalicious
Kasperskynot-a-virus:RiskTool.Win32.IMEStartup.wpk
NANO-AntivirusTrojan.Win32.TrjGen.dagpjd
RisingTrojan.Win32.Generic.14B1CE9D (C64:YzY0OqHufxU8obJP)
ZillyaTool.IMEStartup.Win32.2008
JiangminRiskTool.IMEStartup.fiw
GoogleDetected
Antiy-AVLRiskWare[RiskTool]/Win32.IMEStartup
XcitiumMalware@#3shmbltrior89
ZoneAlarmnot-a-virus:RiskTool.Win32.IMEStartup.wpk
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/ABRisk.UCRW-7788
McAfeeArtemis!277E660F7534
Cylanceunsafe
YandexRiskware.IMEStartup!HS0cXyHkBzI
IkarusTrojan.Rogue
MaxSecureTrojan.Malware.300983.susgen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Risktool.Generic.21436?

Risktool.Generic.21436 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment