Risk

Should I remove “VHO:RiskTool.Win32.Gamehack”?

Malware Removal

The VHO:RiskTool.Win32.Gamehack is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:RiskTool.Win32.Gamehack virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine VHO:RiskTool.Win32.Gamehack?


File Info:

name: F5FE49351B39FA0E0F6C.mlw
path: /opt/CAPEv2/storage/binaries/81bbeb624cc29de004dd50a8a38cd086c62c4eec1d1e8c7ae7f2aacde1cb48e5
crc32: F1A0B238
md5: f5fe49351b39fa0e0f6cc550a201bed0
sha1: 94badf20b4b3127c941d589f0d1bc9ceaae90124
sha256: 81bbeb624cc29de004dd50a8a38cd086c62c4eec1d1e8c7ae7f2aacde1cb48e5
sha512: 799cb48cade8a54f5bece5fdb98da5316be7e253fdbcf3c8767f89fd977bff336b936da90061711dfc82d6d71c5acaa3fbf6ae2f7767044fc71588a2d1cc21b9
ssdeep: 98304:zalsGbbwoNNOg26GQdJnqs+4lEaf1bxZdlNKnyZlPl2xHNWmpaIeUa3jp8jPAOhH:2tfxNZZJqsRnPw0Zl2ZpajF8ssjC5i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A176338426A0A1E1EC02C4FE4E4D5375E3158E11F9E3AB7A95743FDB213DAE614ACF18
sha3_384: b9767d6becbd212ca8ad5d90ab3706329d06b7f15a61ac07572d9966da0528509d6641d2cfad41cc126d72ee2d35ec12
ep_bytes: 60c744241c9da74fc5881c24c7442418
timestamp: 2022-08-26 08:37:33

Version Info:

FileVersion: 1.0.0.0
FileDescription: 自定义UI
ProductName: 自定义UI
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

VHO:RiskTool.Win32.Gamehack also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.925615
FireEyeGeneric.mg.f5fe49351b39fa0e
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004b8e1b1 )
K7GWAdware ( 004b8e1b1 )
Cybereasonmalicious.51b39f
CyrenW32/Agent.BPM.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/FlyStudio.Packed.AE potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:VHO:RiskTool.Win32.Gamehack.gen
BitDefenderGen:Variant.Ursu.925615
Ad-AwareGen:Variant.Ursu.925615
EmsisoftGen:Variant.Ursu.925615 (B)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
VIPREGen:Variant.Ursu.925615
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminemalicious.moderate.ml.score
SophosMal/VMProtBad-A
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.Kryptik.HK@susp
GoogleDetected
AhnLab-V3Packed/Win32.Vmpbad.C90402
BitDefenderThetaGen:NN.ZexaF.34698.@B0@a8m4iinb
ALYacGen:Variant.Ursu.925615
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Generic@AI.99 (RDML:svzQO0odX4XhInC6oD2xIw)
MaxSecureDropper.Dinwod.frindll
CrowdStrikewin/malicious_confidence_70% (D)

How to remove VHO:RiskTool.Win32.Gamehack?

VHO:RiskTool.Win32.Gamehack removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment