Crack Risk

WinActivator.HackTool.RiskWare.DDS removal tips

Malware Removal

The WinActivator.HackTool.RiskWare.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinActivator.HackTool.RiskWare.DDS virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine WinActivator.HackTool.RiskWare.DDS?


File Info:

name: D6D67F1A77E2A92B02DB.mlw
path: /opt/CAPEv2/storage/binaries/b1d8325dbec87c540f8a256d1978619420fa06e39675ad684427a93c73edede1
crc32: 4077DE93
md5: d6d67f1a77e2a92b02db3cf2c107e493
sha1: cc7026bcdda465444f2d4b6ec6671d309461c10a
sha256: b1d8325dbec87c540f8a256d1978619420fa06e39675ad684427a93c73edede1
sha512: 5142669485b177f8d05e4e86e4e00afab05e8b247a3609c554477490258c78e3ff3c836a3ffeb229a87dc9dff45af5f9258820ee1dfa21fa5b7eaf3ba6a6396a
ssdeep: 49152:PEYJFEWn+4NWcNKg/ngk4mY0bI1Wymfgvn81yJffTpuWV355FXw/+cuWV355FXwZ:PEYUI8cgg/ngk4mYfA7fgvn812nvkc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139165A64A7223073E48A64720092D5374A243D34771A26679BCFDC9F3AF95CAEB5C327
sha3_384: 620dcce646f48d948cf80adf594903855cba96534a4e6b32bc81538266841d8c2ea745ce1ab2c96123cb483993ad2e48
ep_bytes: e90413fcff008dbe0060e7ff5789e58d
timestamp: 2007-10-31 16:53:19

Version Info:

CompanyName:
FileVersion: 2.2.1.0
Country:
Release: Final
FileDescription:
LegalCopyright:
ProductVersion:
ProductName:
OriginalFilename: Windows Loader.exe
InternalName:

WinActivator.HackTool.RiskWare.DDS also known as:

BkavW32.FloxitNV.PE
LionicVirus.Win32.Pioneer.n!c
MicroWorld-eScanDropped:Trojan.AgentWDCR.ERJ
FireEyeDropped:Trojan.AgentWDCR.ERJ
McAfeeDropper-FIY!D6D67F1A77E2
Cylanceunsafe
ZillyaVirus.Floxif.Win32.1
SangforVirus.Win32.Save.Floxif
K7AntiVirusUnwanted-Program ( 004bc1f91 )
AlibabaVirus:Win32/Floxif.gen1
K7GWUnwanted-Program ( 004bc1f91 )
Cybereasonmalicious.a77e2a
VirITWin32.FloodFix.A
CyrenW32/Floxif.B
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ClamAVWin.Virus.Pioneer-9111434-0
KasperskyVirus.Win32.Pioneer.cz
BitDefenderDropped:Trojan.AgentWDCR.ERJ
AvastWin32:Pioneer-C
TencentVirus.Win32.Pionner.tt
SophosW32/Floxif-G
F-SecureMalware.W32/Floxif.hdc
DrWebWin32.FloodFix.7
VIPREDropped:Trojan.AgentWDCR.ERJ
TrendMicroPE_FLOXIF.D
McAfee-GW-EditionDropper-FIY!D6D67F1A77E2
EmsisoftDropped:Trojan.AgentWDCR.ERJ (B)
IkarusVirus.Win32.Floxif.A
GDataDropped:Trojan.AgentWDCR.ERJ
JiangminWin32/Pioneer.l
GoogleDetected
AviraW32/Floxif.hdc
Antiy-AVLVirus/Win32.Pioneer.cz
ArcabitTrojan.AgentWDCR.ERJ
ZoneAlarmVirus.Win32.Pioneer.cz
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacDropped:Trojan.AgentWDCR.ERJ
MAXmalware (ai score=89)
MalwarebytesWinActivator.HackTool.RiskWare.DDS
PandaW32/Floxif.A
TrendMicro-HouseCallPE_FLOXIF.D
RisingVirus.Floxif!1.9BE6 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Pioneer.CZ
AVGWin32:Pioneer-C
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove WinActivator.HackTool.RiskWare.DDS?

WinActivator.HackTool.RiskWare.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment