Risk

Should I remove “RiskTool.Generic”?

Malware Removal

The RiskTool.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Generic virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: u1404.exe
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
s3-ap-southeast-1.amazonaws.com
a.tomx.xyz
s3.amazonaws.com
www.urubkgn.info
www.kbdhgjmg.info
d1mi1rhnhzmk37.cloudfront.net
www.bxezdojb.info

How to determine RiskTool.Generic?


File Info:

crc32: 03F5E08C
md5: 96277ff94da577cfcbc72568cb43cfd7
name: u1404.exe
sha1: fe9efaaf1879e37eaf42166b484f32142e65af64
sha256: 8fd612fddc0cd96a481f445c9862ec92c47da96652ccf1105ade871493a54ce7
sha512: 527494b53dea97196f9761762a5fde13db204ada257636771a44a35ba723b49e83112d9d2366fdfd48da2eaa67421b5676beba38202fe0987d4c4a98923fa937
ssdeep: 49152:0NtV7H75U78IdqbPre24vWaLU7kQRCmJU7:0NHD7Jg+re2Vgbr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

RiskTool.Generic also known as:

BkavW32.HfsAdware.961F
CAT-QuickHealRiskTool.Generic
CylanceUnsafe
VIPREUltrasurf (not malicious)
AegisLabRiskware.Win32.Generic.1!c
K7AntiVirusUnwanted-Program ( 004badc31 )
K7GWUnwanted-Program ( 004badc31 )
Invinceaheuristic
APEXMalicious
ViRobotAdware.Ultrasurf.2111200
RisingMalware.Undefined!8.C (CLOUD)
Endgamemalicious (high confidence)
DrWebTool.UltraSurf.11
ZillyaExploit.CVE.Win32.478
TrendMicroHackTool.Win32.UltraSurf.AC
MaxSecureTrojan.Malware.710517.susgen
FireEyeGeneric.mg.96277ff94da577cf
IkarusTrojan.Agent
JiangminRiskTool.Generic.hee
MicrosoftPUA:Win32/Presenoker
VBA32Trojan.Downloader
ESET-NOD32a variant of Win32/UltraReach potentially unsafe
TrendMicro-HouseCallHackTool.Win32.UltraSurf.AC
YandexRiskware.UltraReach!
FortinetRiskware/UltraReach

How to remove RiskTool.Generic?

RiskTool.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment