Malware

Win32/Caosoft.A potentially unwanted removal guide

Malware Removal

The Win32/Caosoft.A potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Caosoft.A potentially unwanted virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify browser security settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Caosoft.A potentially unwanted?


File Info:

name: 29BF9BD1B052DC38D79D.mlw
path: /opt/CAPEv2/storage/binaries/ca9d917ea5eb8236ea5ef3e80274852851f98cceb0e141b32bbfd8d9ea5c6b5a
crc32: 1E125E25
md5: 29bf9bd1b052dc38d79dc03e4cf15ec0
sha1: 678a8d099315564c3f487e56c4e91bb1ee7c546f
sha256: ca9d917ea5eb8236ea5ef3e80274852851f98cceb0e141b32bbfd8d9ea5c6b5a
sha512: 918fe594e30fc2ed74607e188d41594cc8ece68c46a03d2663a4aa91763a1f3b879132eadd6deaf6842615f07b6350272e3a02f6ef4c7faa4adf3001597626b7
ssdeep: 49152:nOgBvi+J4ZEn1oIxpte+6Ix96NjM59h69NmthJsC9jCsBPugTOqV2RkD:OKvpJ4mn6Ile+6I2S5z6fmtflvBPugTN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAA5335744D62DF3E841BC301A24F8C1A60464631EAB79743E42DECAC975DCEE3E2A5B
sha3_384: 7fd6394f9712bd25931649b9805c70c943a8ba97f4be9c713b58a52fd464df42d7067e5e7236ccf6706db2cd7b77ce1f
ep_bytes: 60be00f04a008dbe0020f5ffc787f419
timestamp: 2012-12-10 02:52:18

Version Info:

CompanyName: 梦泰尔软件工作室MTSoftware(CN)
FileDescription: Print Control (32-bit) Install
FileVersion: 6.1.3.9
InternalName: Print Control Install
LegalCopyright: 梦泰尔软件工作室MTSoftware(CN)
LegalTrademarks: Lodop
OriginalFilename: PrintControl_Install.exe
ProductName: PrintControl_Install
ProductVersion: 6.1
Comments: 梦泰尔软件工作室MTSoftware(CN)
Translation: 0x0804 0x03a8

Win32/Caosoft.A potentially unwanted also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.67779537
FireEyeTrojan.GenericKD.67779537
McAfeeArtemis!29BF9BD1B052
Cylanceunsafe
SangforTrojan.Win32.Agent.V4uj
K7AntiVirusAdware ( 005892391 )
K7GWAdware ( 005892391 )
ArcabitTrojan.Generic.D40A3BD1
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Caosoft.A potentially unwanted
APEXMalicious
BitDefenderTrojan.GenericKD.67779537
AvastFileRepMalware [Misc]
EmsisoftTrojan.GenericKD.67779537 (B)
VIPRETrojan.GenericKD.67779537
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.67779537
VBA32Adware.DealPly
ALYacTrojan.GenericKD.67779537
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.R002H09FS23
FortinetMalicious_Behavior.SB
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS

How to remove Win32/Caosoft.A potentially unwanted?

Win32/Caosoft.A potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment