Risk

UDS:RiskTool.Win32.IMEStartup.ah removal guide

Malware Removal

The UDS:RiskTool.Win32.IMEStartup.ah is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:RiskTool.Win32.IMEStartup.ah virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine UDS:RiskTool.Win32.IMEStartup.ah?


File Info:

crc32: 533E9941
md5: 57004f1ea831e85f5b434ade69d11ed0
name: 57004F1EA831E85F5B434ADE69D11ED0.mlw
sha1: 1502e637a39cea76a062aaec7b12be61636d5fc0
sha256: 653f9eb0a1cd6101601fb33914910dde2763c74f5b4ae3105992c7e6ddee2d5e
sha512: f292b923a78e9ee09bcf39c89bb4e326c10899323f7a812f3f4a2af6175238debe6c389714fba39dea98f6053e949f273055cb4ed4d332d2be77cde584025df8
ssdeep: 24576:WAc3NYfNozrHXZ5rDwCeFbifEVTf7YykqywSiJzPkFeO2EeM:WAcBzrnnwCOWfEzkq22zMdD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Qizhe Focus on LOL Vision Tool
FileVersion: 1.0.0.0
CompanyName: x542fx8005
Comments: Qizhe Focus on LOL Vision Tool
ProductName: Master Chen
ProductVersion: 1.0.0.0
FileDescription: Qizhe Focus on LOL Vision Tool
Translation: 0x0804 0x04b0

UDS:RiskTool.Win32.IMEStartup.ah also known as:

K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic.2919
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaRiskWare:Win32/FlyStudio.96a81dab
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.7a39ce
BaiduWin32.Trojan.FakeIME.d
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Malware.Onlinegames-6629257-0
Kasperskynot-a-virus:UDS:RiskTool.Win32.IMEStartup.ah
TencentWin32.Trojan.Imeinject.Stka
SophosGeneric PUA BF (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34790.3r0@aCLAf7ob
TrendMicroTROJ_GEN.R005C0PFU21
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.57004f1ea831e85f
SentinelOneStatic AI – Malicious PE
JiangminPacked.Vemply.adr
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.19Q2126
AhnLab-V3Suspicious/Win.Evo-gen.C4539347
Acronissuspicious
McAfeeGenericRXEQ-GI!57004F1EA831
VBA32BScope.Downloader.Snojan
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R005C0PFU21
RisingHackTool.GameHack!1.B2A6 (CLASSIC)
IkarusTrojan.Win32.MBRlock
MaxSecureTrojan.Kolovorot.in
FortinetW32/CoinMiner.ELG!tr.pws
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove UDS:RiskTool.Win32.IMEStartup.ah?

UDS:RiskTool.Win32.IMEStartup.ah removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment