Risk

How to remove “UDS:RiskTool.Win32.IMEStartup.jxk”?

Malware Removal

The UDS:RiskTool.Win32.IMEStartup.jxk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:RiskTool.Win32.IMEStartup.jxk virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine UDS:RiskTool.Win32.IMEStartup.jxk?


File Info:

name: EA43CC41FAFF76704D9C.mlw
path: /opt/CAPEv2/storage/binaries/9000140f0c07c3c307ab13e73ccb59f31d08b0186d44df76b7386c98126f56e9
crc32: 36C7A7EB
md5: ea43cc41faff76704d9c0b9ad1e1d4e5
sha1: 68cb83e88a076bfa865d0ba027edf9a42d8bbb8e
sha256: 9000140f0c07c3c307ab13e73ccb59f31d08b0186d44df76b7386c98126f56e9
sha512: 514b92b4bcf9b361abb0d69ab94e402629ad27037c175185022354dce336f8dfab8b98baa754b556f17c75e122386383be62e4c3221da0b6d5699c6ed949f6c3
ssdeep: 98304:KI65HaN+2nTS4qnvYJz9b7fFy++Hevi8/j9ZiCRFnvRZe1mgskgMrqhCU/Ew1y54:qVO7e4qvYJz9nFYm9Zi4Fn5vzkyg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1274633C73FB6413AD5148C7055D0BDE10A3FCD147CAEBA0CB935F0AA7A7658862634BA
sha3_384: 0ce71d926f25b296d36c5c9f9d9d2903bf92cb27ef8178b5b4d31dca9630054ccc9095a9dce6983145fb8e4a8c10d882
ep_bytes: 60be00c06a008dbe0050d5ff5789e58d
timestamp: 2021-09-06 14:20:52

Version Info:

FileVersion: 3.0.0.0
FileDescription: 模拟人工按键或点击,解放双手。
ProductName: 通用按键
ProductVersion: 3.0.0.0
CompanyName: 大山QQ396877989
LegalCopyright: 本软件为易语言加大漠插件所原创,仅作测试使用,切勿随意传播、修改、和用于商业行为。 软件本身不带任何病毒,如杀毒软件报毒实属因使用了其它插件而误报,请添加信任或直接删除本程序。
Comments: 主要使用大漠插件,易语言编译,360会误报,火绒不报。
Translation: 0x0804 0x04b0

UDS:RiskTool.Win32.IMEStartup.jxk also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.IMEStartup.1!c
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.ea43cc41faff7670
CylanceUnsafe
SangforRiskware.Win32.IMEStartup.jxk
K7AntiVirusAdware ( 005848221 )
AlibabaRiskWare:Win32/IMEStartup.dc184b1b
K7GWAdware ( 005848221 )
Cybereasonmalicious.88a076
BitDefenderThetaGen:NN.ZexaF.34606.@pKfaK6GgHfH
CyrenW32/OnlineGames.HI.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CBO22
Paloaltogeneric.ml
Kasperskynot-a-virus:UDS:RiskTool.Win32.IMEStartup.jxk
AvastFileRepMalware [Misc]
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
ZillyaTool.IMEStartup.Win32.1368
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA GI (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1DNV50E
JiangminRiskTool.IMEStartup.evq
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!EA43CC41FAFF
APEXMalicious
RisingHacktool.IMEStartup!8.13A5B (CLOUD)
MaxSecureTrojan.Malware.73738457.susgen
FortinetW32/CoinMiner.65CA!tr
AVGFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove UDS:RiskTool.Win32.IMEStartup.jxk?

UDS:RiskTool.Win32.IMEStartup.jxk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment