Crack Risk

Win32/RiskWare.GameHack.DP removal guide

Malware Removal

The Win32/RiskWare.GameHack.DP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RiskWare.GameHack.DP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics

How to determine Win32/RiskWare.GameHack.DP?


File Info:

name: 024D01B586160DD83018.mlw
path: /opt/CAPEv2/storage/binaries/370c3343cf047d1563c5cb5ee1cc8b0012774fe3557fb35f378129f0a722c093
crc32: 0F237DBB
md5: 024d01b586160dd83018bbecf13818ae
sha1: 631f5914c1978e67d18954216dd9f2bc061b95df
sha256: 370c3343cf047d1563c5cb5ee1cc8b0012774fe3557fb35f378129f0a722c093
sha512: c07ac9501793de68fb712449df3587585e5500b0423e618def145300adccb032e89e40910858c22290e3aaca591af14604129b37fd9f714b608c259f283dbc65
ssdeep: 98304:vj/rk6U/WYCXWeZje8tNJj669cERHEkN+nCF9L8Tamfiso6zaSwIfeaG4I:vk6U+YCXWe88tUdkSCFx8nfu6GQev
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1676633F2BAC3D6E3F0AE09BC130D8B539510964C71D39B4F037927B7DD6A25869C9928
sha3_384: d67a82c9aca91bcd79620aa122181a059eb57ef174371e4482b0415d0ef5c10bcc1b4ad08b4569be9ad1ca027ccc5be7
ep_bytes: 9cc70424fd80318060c744241c023805
timestamp: 2016-07-21 09:15:59

Version Info:

0: [No Data]

Win32/RiskWare.GameHack.DP also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
SkyhighArtemis!Trojan
Cylanceunsafe
SangforRiskware.Win32.Agent.Vghe
K7AntiVirusRiskware ( 0055997e1 )
AlibabaRiskWare:Win32/OnlineGames.ff8ef5a0
K7GWRiskware ( 0055997e1 )
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/RiskWare.GameHack.DP
APEXMalicious
ClamAVWin.Trojan.Graybird-9791241-0
NANO-AntivirusRiskware.Win32.Mutabaha.hwopzj
RisingHacktool.GameHack!8.59E (CLOUD)
GoogleDetected
F-SecureHeuristic.HEUR/AGEN.1333667
DrWebAdware.Mutabaha.1510
FireEyeGeneric.mg.024d01b586160dd8
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Spy.Banker
VaristW32/OnlineGames.CP.gen!Eldorado
AviraHEUR/AGEN.1333667
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win32.GameClient.R338021
McAfeeArtemis!024D01B58616
VBA32BScope.Trojan.MulDrop
MalwarebytesMachineLearning/Anomalous.100%
YandexTrojan.GenAsa!J37LVkWa71A
SentinelOneStatic AI – Suspicious PE
BitDefenderThetaGen:NN.ZexaF.36802.@RZ@aKM64ekj
DeepInstinctMALICIOUS

How to remove Win32/RiskWare.GameHack.DP?

Win32/RiskWare.GameHack.DP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment