Adware

Adware.Eszjuxuan removal instruction

Malware Removal

The Adware.Eszjuxuan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Eszjuxuan virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Authenticode signature is invalid

Related domains:

wpad.local-net

How to determine Adware.Eszjuxuan?


File Info:

name: 4C0C1E3EF9E6B53AA611.mlw
path: /opt/CAPEv2/storage/binaries/d2589df96aeba62d0d2207225d5a9342fd52f034a174cd71b5c584abf772ce6f
crc32: 9AED7B79
md5: 4c0c1e3ef9e6b53aa61141def1d1b0b2
sha1: 5cb70b6dc38319f4b60e206accd6c4d7f31034c8
sha256: d2589df96aeba62d0d2207225d5a9342fd52f034a174cd71b5c584abf772ce6f
sha512: 520499d260c8f2eb36bb434fd6016770a79cbe53929a8439db86dd44eff09421596b6b79bc8f390cc4c142517153d2309fcb6040d9a7efccc68d54d0843ec233
ssdeep: 24576:bKethlo9tcmg1bY+jQ9vbv3eiBPEDYXd97J+xw6wJ45Bjie6R/Hxx:WebYhzveiBsDC9WRBWe6R/Hx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180754A10A501E23AE9F305FACEBE564D956CFF10171824CBA3CC2D6E5BA6AE17D31127
sha3_384: 734962dc0b3800769606288eaa724d11437a43230372b0e4579acc90d2fbc07fda68ae983d1cf7f174edc383b12201d5
ep_bytes: e80fe00000e97bfeffff3b0d4c395700
timestamp: 2016-07-18 06:13:48

Version Info:

0: [No Data]

Adware.Eszjuxuan also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Razy.62899
FireEyeGeneric.mg.4c0c1e3ef9e6b53a
ALYacGen:Variant.Application.Razy.62899
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Generic.5
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Application.Razy.62899
K7GWAdware ( 004e10191 )
K7AntiVirusAdware ( 004e10191 )
ArcabitTrojan.Application.Razy.DF5B3
BitDefenderThetaGen:NN.ZexaF.34062.IvW@amK3THli
CyrenW32/S-5de092b7!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Eszjuxuan.A
TrendMicro-HouseCallTROJ_GEN.R002C0PIG21
Paloaltogeneric.ml
ClamAVWin.Malware.5de092b-9880069-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Sokuxuan.gen
AlibabaAdWare:Win32/Sokuxuan.c6a793b8
NANO-AntivirusRiskware.Win32.Eszjuxuan.eemnsr
ViRobotTrojan.Win32.Z.Eszjuxuan.1609728
RisingTrojan.Generic@ML.100 (RDML:bAZN7MjR7k8IySEI0UcIug)
Ad-AwareGen:Variant.Application.Razy.62899
SophosGeneric PUA FM (PUA)
TrendMicroTROJ_GEN.R002C0PIG21
McAfee-GW-EditionBehavesLike.Win32.Adware.th
EmsisoftGen:Variant.Application.Razy.62899 (B)
APEXMalicious
JiangminTrojanDownloader.Agent.fjbr
AviraHEUR/AGEN.1118494
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.19C89FA
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywarePUP.ELEX/Variant
GDataGen:Variant.Application.Razy.62899
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Eszjuxuan.R184698
McAfeeGenericRXAH-WK!4C0C1E3EF9E6
VBA32Adware.Sokuxuan
MalwarebytesAdware.Eszjuxuan
IkarusPUA.Eszjuxuan
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b76f9a
YandexPUA.Eszjuxuan!WgU1kGMnol8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.361071!tr
AVGWin32:Adware-gen [Adw]
AvastWin32:Adware-gen [Adw]

How to remove Adware.Eszjuxuan?

Adware.Eszjuxuan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment