Risk

RiskTool.Win32.HideExec.h removal guide

Malware Removal

The RiskTool.Win32.HideExec.h is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.HideExec.h virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine RiskTool.Win32.HideExec.h?


File Info:

crc32: D274430A
md5: e2b2b3b0e60f6e3b7a2a39f8586caeb0
name: E2B2B3B0E60F6E3B7A2A39F8586CAEB0.mlw
sha1: a7cd8792029cb2378783ee269fd0779007213f11
sha256: 89ea757d139699090e976bd9fcb2bbcd96733dea25f4c06cf1a1093783657f4b
sha512: 24fec29471f52954abd4b054616167ed663a1bc1ea3a2977b8b0a553c801be9834bfc15d1c060421cf22b3107caa78638614b90f07628069d4894e72d203bda5
ssdeep: 768:zBC7q+QB4wlq92UaYYCfT6DYLJN9lMxEpHqlKx1izQgBFb0QsEhSmxYWfo:87q+Qy2j7CLxMxWUjLzKh
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: HideCMD
FileVersion: 0.6.0.4
ProductName: HideCMD V06.04
ProductVersion: 06.04
FileDescription: x9690x85cfx8fd0x884cx6279x5904x7406x547dx4ee4
OriginalFilename: HideCMD.EXE
Translation: 0x0804 0x03a8

RiskTool.Win32.HideExec.h also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004bcce41 )
LionicTrojan.Win32.Generic.lvQj
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.eq0@!3MZS2kb
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.0e60f6
CyrenW32/Risk.WZNT-7061
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/HideExec.NAJ potentially unsafe
APEXMalicious
AvastWin32:Evo-gen [Susp]
Kasperskynot-a-virus:RiskTool.Win32.HideExec.h
BitDefenderGen:Trojan.Heur.eq0@!3MZS2kb
NANO-AntivirusRiskware.Win32.HideExec.fgogzb
ViRobotRiskTool.HideExec.77568
MicroWorld-eScanGen:Trojan.Heur.eq0@!3MZS2kb
Ad-AwareGen:Trojan.Heur.eq0@!3MZS2kb
ComodoApplicUnsaf.Win32.HideExec.A@640g
BitDefenderThetaAI:Packer.64E53C9D1C
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.e2b2b3b0e60f6e3b
EmsisoftGen:Trojan.Heur.eq0@!3MZS2kb (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
KingsoftWin32.Troj.Generic.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Trojan.Heur.eq0@!3MZS2kb
Acronissuspicious
McAfeeArtemis!E2B2B3B0E60F
MAXmalware (ai score=80)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CK321
YandexRiskTool.HideExec!qJrOVYwr14U
IkarusTrojan-Dropper.Delf
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove RiskTool.Win32.HideExec.h?

RiskTool.Win32.HideExec.h removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment