Risk

About “RiskWare.GameTool” infection

Malware Removal

The RiskWare.GameTool is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.GameTool virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine RiskWare.GameTool?


File Info:

crc32: 1B43457D
md5: 0eee8a839c6584e708885b20c25b4ee7
name: 0EEE8A839C6584E708885B20C25B4EE7.mlw
sha1: e0ac9a639193f86486213c0dcc086797db55b4a3
sha256: 2a1d487c7ad4675a3dd1a36c637ee6e2af2d1da25fc479ee042eb312c7e45362
sha512: ceb93b4a3254a06ba0a45d58b7437fecaf967c0fa8380e58f5f78c01ad975918b5f828a64d8d8e8dd30ff1cc3e958a961a1d9d3dcb2925711bb4b11aa8b4a9b1
ssdeep: 24576:Nak/7Nk4RZsRDKHxoa0ahm+3qMOA/6GsBGUNNqVjk07z8oDqE:Nak/ilKHn0amXAJsBLNNWg07Io+E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2010
InternalName: LoginTools.exe
FileVersion: 1,0,0,0
CompanyName: 178x7f51x6e38x5de5x4f5cx5ba4
ProductName: x5546x4e1ax7a0bx5e8f
ProductVersion: 1, 0, 0, 0
FileDescription: x5546x4e1ax7a0bx5e8f
OriginalFilename: LoginTools.exe
Translation: 0x0804 0x03a8

RiskWare.GameTool also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader35.4463
MicroWorld-eScanGen:Variant.Bulz.134753
FireEyeGeneric.mg.0eee8a839c6584e7
ALYacGen:Variant.Bulz.134753
MalwarebytesRiskWare.GameTool
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Bulz.4!c
K7AntiVirusRiskware ( 005439d61 )
BitDefenderGen:Variant.Bulz.134753
K7GWRiskware ( 005439d61 )
Cybereasonmalicious.39c658
BitDefenderThetaGen:NN.ZelphiF.34804.qT0ba4XgWvdi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R03BC0DAV21
Paloaltogeneric.ml
AlibabaTrojanPSW:Win32/ManBat.19338c44
NANO-AntivirusTrojan.Win32.GameTool.iirwvd
RisingMalware.Lmir!8.E96A (CLOUD)
Ad-AwareGen:Variant.Bulz.134753
SophosMal/Generic-S
ComodoMalware@#1wg6qkh7nhu48
F-SecureHeuristic.HEUR/AGEN.1103850
TrendMicroTROJ_GEN.R03BC0DAV21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Bulz.134753 (B)
IkarusTrojan.ManBat
AviraHEUR/AGEN.1103850
MAXmalware (ai score=82)
Antiy-AVLTrojan[PSW]/Win32.Lmir
MicrosoftPWS:Win32/Lmir.BMQ
GridinsoftTrojan.Win32.Downloader.oa
GDataGen:Variant.Bulz.134753
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Generic.R329115
McAfeeGenericRXAA-FA!0EEE8A839C65
VBA32Trojan.SDP.27105
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/RiskWare.GameTool.S
TencentMalware.Win32.Gencirc.10ce0c5c
YandexRiskWare.GameTool!pMU37xFVQRE
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Fugrafa.7364!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Generic/Trojan.156

How to remove RiskWare.GameTool?

RiskWare.GameTool removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment