Malware

About “AdWare.Win32.ICLoader.ijhz” infection

Malware Removal

The AdWare.Win32.ICLoader.ijhz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.ICLoader.ijhz virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine AdWare.Win32.ICLoader.ijhz?


File Info:

crc32: F81F27E2
md5: f3195e8c0c1a427771406b17fd797233
name: F3195E8C0C1A427771406B17FD797233.mlw
sha1: 96f0ea7e57913ca60cefc3a5e7ab48a0802ed20a
sha256: dd9db56badc31115a61f5d5235d18414801e818d5cfa87a01d878dac0b7b1f53
sha512: 31152ecdedbf6380fafdb3a79efae73efcdb76d74c976f049f604732bae3854e8521bce1b48e2820c600d0c482b4b3989efdff2b18c86c8b312a989c68a60c3a
ssdeep: 12288:6g8qvgmY51xAR+dbuJlg/gQ5lpNE20GbtK2q2TaRx2O:Aq5s1xAR+6liE20GU2q22Rx
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: YHVUPL I
InternalName: dnipoegwagq
FileVersion: 8.17.134.59087
CompanyName: IACB IPHO Q
LegalTrademarks: ALYEWO Alk
ProductName: kgouhobi o
ProductVersion: 8.17.134.59087
FileDescription: Giixyy Z
OriginalFilename: uyrunga.exe
Translation: 0x0409 0x04b0

AdWare.Win32.ICLoader.ijhz also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
DrWebTrojan.StartPage1.49458
ALYacGen:Variant.Jaik.42036
CylanceUnsafe
ZillyaAdware.HPDefender.Win32.3059
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWAdware ( 005319761 )
K7AntiVirusAdware ( 005319761 )
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.ICLoader.ijhz
BitDefenderGen:Variant.Jaik.42036
NANO-AntivirusRiskware.Win32.HPDefender.ezaycy
MicroWorld-eScanGen:Variant.Jaik.42036
TencentWin32.Adware.Icloader.Dzsz
Ad-AwareGen:Variant.Jaik.42036
SophosGeneric PUA JG (PUA)
ComodoApplicUnwnt@#10psqqux6wdw7
BitDefenderThetaGen:NN.ZexaF.34170.sy0@aSiCYZfi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PIH21
McAfee-GW-EditionBehavesLike.Win32.ICLoader.fc
FireEyeGeneric.mg.f3195e8c0c1a4277
EmsisoftGen:Variant.Jaik.42036 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117983
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywareAdware.HPDefender/Variant
GDataGen:Variant.Jaik.42036
AhnLab-V3PUP/Win32.HPDefender.R307750
McAfeeICLoader
MAXmalware (ai score=97)
VBA32BScope.Trojan.StartPage
MalwarebytesAdware.HPDefender
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PIH21
RisingTrojan.Generic@ML.100 (RDMK:vvqTraw9xf0djj/hJGmYJA)
YandexTrojan.GenAsa!hchNbLSEvMI
FortinetRiskware/HPDefender
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.ICLoader.ijhz?

AdWare.Win32.ICLoader.ijhz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment