Malware

AdWare.Win32.ICLoader.ijfw removal instruction

Malware Removal

The AdWare.Win32.ICLoader.ijfw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.ICLoader.ijfw virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AdWare.Win32.ICLoader.ijfw?


File Info:

crc32: 8447DD6A
md5: 9f3737f868f06a151b0fc30c80b795e4
name: 9F3737F868F06A151B0FC30C80B795E4.mlw
sha1: c82d96fe4eb94d6d801d84cadb91edb62af1e069
sha256: 205bfec2c17c3fef2e161c32c3d719761f82f8ae4e44b556fb096b40cfc0617a
sha512: 6122e75ce59ec7ce56c9d3920dab4bf58e5bab41ee87e39515787d77110bcb0b7e7e52ea57ab56b320c4b2d3186824d57e330970d3ce8e4b0b262634a770751e
ssdeep: 12288:6g8z+SardLSoSpjf/US4CgvyDFLEWJKdoE9ypSq:AKSahOjHUpvoFQIKdoX
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: YHVUPL I
InternalName: dnipoegwagq
FileVersion: 8.17.134.59087
CompanyName: IACB IPHO Q
LegalTrademarks: ALYEWO Alk
ProductName: kgouhobi o
ProductVersion: 8.17.134.59087
FileDescription: Giixyy Z
OriginalFilename: uyrunga.exe
Translation: 0x0409 0x04b0

AdWare.Win32.ICLoader.ijfw also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 005319761 )
Elasticmalicious (high confidence)
DrWebTrojan.StartPage1.49458
CynetMalicious (score: 100)
ALYacGen:Variant.Jaik.42036
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWAdware ( 005319761 )
Cybereasonmalicious.868f06
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.ICLoader.ijfw
BitDefenderGen:Variant.Jaik.42036
NANO-AntivirusRiskware.Win32.HPDefender.ezaycy
MicroWorld-eScanGen:Variant.Jaik.42036
TencentWin32.Adware.Icloader.Hvjb
Ad-AwareGen:Variant.Jaik.42036
SophosGeneric PUA MI (PUA)
ComodoApplicUnwnt@#164i405ylreg5
BitDefenderThetaGen:NN.ZexaF.34294.sy0@aSiCYZfi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PIH21
McAfee-GW-EditionBehavesLike.Win32.ICLoader.fc
FireEyeGeneric.mg.9f3737f868f06a15
EmsisoftGen:Variant.Jaik.42036 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117983
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywareAdware.HPDefender/Variant
GDataGen:Variant.Jaik.42036
AhnLab-V3PUP/Win32.HPDefender.R307750
McAfeeICLoader
MAXmalware (ai score=97)
VBA32BScope.Trojan.StartPage
MalwarebytesAdware.HPDefender
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PIH21
RisingTrojan.Generic@ML.100 (RDMK:vvqTraw9xf0djj/hJGmYJA)
YandexTrojan.GenAsa!hchNbLSEvMI
FortinetRiskware/HPDefender
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.ICLoader.ijfw?

AdWare.Win32.ICLoader.ijfw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment