Risk

Should I remove “Win32/RiskWare.DKSoft.A”?

Malware Removal

The Win32/RiskWare.DKSoft.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RiskWare.DKSoft.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/RiskWare.DKSoft.A?


File Info:

name: B9F8DD0A5451FA77033C.mlw
path: /opt/CAPEv2/storage/binaries/a39fb015df8bed86fcaa0af7462a3eeb75f016e339c55a4b8273e6048ecd797a
crc32: 977112B4
md5: b9f8dd0a5451fa77033c2de0250c1de8
sha1: 15abcaa4b23979c770847117f3af1231f320bbcf
sha256: a39fb015df8bed86fcaa0af7462a3eeb75f016e339c55a4b8273e6048ecd797a
sha512: ec4c511a89b82beb0aa30f41dda7b2cb51c6f599266c0ca127c93870c6f2add7056f71fe008ab438f45597d575c96245a737ecdf315a46cc61591ad1d001cfdc
ssdeep: 98304:llxzRE4K7+YSxyJ1QTbsDguzqC6c4twbdJwmRr:bvc7pSxo1QEDL1Swbdxr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15516330EB1EAF43AD8455270E520A942D533B355B43A198F0DF6E8EF4A36C57EE4CB06
sha3_384: e129a2db7c2dd62ce728cea6a62f96f441a6450842b722bb584d7c0d54be076b3917596797346d6f657e0d5a182f22e6
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: DKSOFT
FileDescription: Controle de Acesso - DKSOFT Setup
FileVersion: 1.0
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Win32/RiskWare.DKSoft.A also known as:

BkavW32.Common.D3890911
LionicTrojan.Win32.Diztakun.4!c
MicroWorld-eScanTrojan.GenericKD.37553835
FireEyeTrojan.GenericKD.37553835
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!B9F8DD0A5451
Cylanceunsafe
SangforTrojan.Win32.Diztakun.Vgza
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Diztakun.cc2453bd
BitDefenderThetaGen:NN.ZelphiCO.36680.zKW@a8X8dahO
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/RiskWare.DKSoft.A
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Diztakun.flw
BitDefenderTrojan.GenericKD.37553835
NANO-AntivirusTrojan.Win32.Diztakun.dvsuvc
AvastWin32:Malware-gen
TencentWin32.Trojan.Diztakun.Fflw
TACHYONTrojan/W32.DP-Diztakun.4241920
SophosMal/Generic-S
DrWebTrojan.MulDrop5.47432
VIPRETrojan.GenericKD.37553835
TrendMicroTROJ_GEN.R002C0WAI24
EmsisoftTrojan.GenericKD.37553835 (B)
IkarusBackdoor.Hupigon
WebrootW32.Trojan.GenKD
Antiy-AVLTrojan/Win32.Diztakun
MicrosoftTrojan:Win32/Ymacco.ABA3
XcitiumMalware@#yuejbtszdy48
ArcabitTrojan.Generic.D23D06AB
ZoneAlarmTrojan.Win32.Diztakun.flw
GDataTrojan.GenericKD.37553835
ALYacTrojan.GenericKD.37553835
MAXmalware (ai score=80)
VBA32Trojan.Diztakun
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WAI24
RisingTrojan.Generic@AI.82 (RDML:15NDTdbs2n8dQmA0wVPznQ)
YandexTrojan.Diztakun!zYIn47zViyY
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Diztakun.FLW!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Win32/RiskWare.DKSoft.A?

Win32/RiskWare.DKSoft.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment