RiskWare.IFEOHijack

Short bio

RiskWare.IFEOHijack is a generic detection for programs that set a debugger for other executables by using the following registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
CurrentVersion\Image File Execution Options\
{name of the intercepted executable}

Some legitimate programs that use this method have been white-listed.

Protection

Malwarebytes protects users from RiskWare.IFEOHijack using real-time protection.

Remediation

Malwarebytes can detect and remove RiskWare.IFEOHijack without further user interaction.

  1. Please download Malwarebytes to your desktop.
  2. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  3. Then click Finish.
  4. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  5. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  6. When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  7. Restart your computer when prompted to do so.

Add an exclusion

When RiskWare.IFEOHijack is detected on your computer, Malwarebytes for Windows does not know if it was authorized. Optimization software, malware, and Potentially Unwanted Programs (PUPs) are known to make these types of changes, hence they are regarded as potentially unwanted.

To have Malwarebytes for Windows ignore Riskware, you must add the detection as an exclusion.

  1. Open Malwarebytes for Windows.
  2. Click Settings, then click theProtection tab.
  3. Scroll down to the bottom.
  4. Turn off Automatically quarantine detected malware.Turning this setting off prevents Malwarebytes for Windows from quarantining the PUM automatically.
  5. Go to the Dashboard, then click Scan Now.
  6. When the Threat Scan Results appear, uncheck the box next to the detected PUM you want to keep.
  7. Click Next.
  8. On the Remaining Items window, click Ignore Always to add the exclude the detected PUM(s).
  9. Turn on Automatically quarantine detected malware.To find this setting, click Settings > Protection.

When RiskWare.IFEOHijack is excluded, Malwarebytes for Windows does not detect RiskWare.IFEOHijack during scans or Real-Time Protection.

Related blog content

An Introduction to Image File Execution Options

How to avoid potentially unwanted programs