Malware

AdWare.Win32.Qjwmonkey.ejz (file analysis)

Malware Removal

The AdWare.Win32.Qjwmonkey.ejz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Qjwmonkey.ejz virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings

Related domains:

w.nanweng.cn
www.msn.com
ocsp.digicert.com
static-global-s-msn-com.akamaized.net

How to determine AdWare.Win32.Qjwmonkey.ejz?


File Info:

crc32: AA989EAF
md5: 7145a179b496fc5fe19dc9b7745e2deb
name: 7145A179B496FC5FE19DC9B7745E2DEB.mlw
sha1: db6434602ca9b8939a468defb9cef89d4ca93d12
sha256: 8e23c6df003309ef656835eab65a8263c88ac0c277ffdbd5307eefdecb23872a
sha512: 91cfe168917e51020c5a4628ef59ee462e2b9d82318d41f10059c3a910e94c8b1dc1ab5763c67a8a3d353893e36581788321f22b7c2c1aaf91df0125d38864e7
ssdeep: 12288:32wvqfb2RbdyP4S54TNPBGauMKS3AsecQx3VD7aE0IpNb0cCbe4dp:GwvqfyW54JBMMGseLnaE04NAfdp
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2021
InternalName: SEMx667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 6.0.0.0603
ProductName: SEMx667ax80fdx4e0bx8f7dx5668.exe
FileDescription: _
OriginalFilename: SEMx667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

AdWare.Win32.Qjwmonkey.ejz also known as:

K7AntiVirusAdware ( 00510c5c1 )
Elasticmalicious (high confidence)
DrWebAdware.Qjwmonkey.168
CynetMalicious (score: 100)
ALYacGen:Variant.Application.Downloader.Nezchi.1
CylanceUnsafe
SangforTrojan.Win32.Qjwmonkey.A
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/Qjwmonkey.52ff9497
K7GWAdware ( 00510c5c1 )
Cybereasonmalicious.9b496f
CyrenW32/Adware.DRHV-6901
SymantecPUA.Downloader
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.K
APEXMalicious
AvastWin32:WormX-gen [Wrm]
Kasperskynot-a-virus:AdWare.Win32.Qjwmonkey.ejz
BitDefenderGen:Variant.Application.Downloader.Nezchi.1
NANO-AntivirusRiskware.Win32.Qjwmonkey.iwgtye
ViRobotAdware.Qjwmonkey.650952
MicroWorld-eScanGen:Variant.Application.Downloader.Nezchi.1
TencentMalware.Win32.Gencirc.11c20c2e
Ad-AwareGen:Variant.Application.Downloader.Nezchi.1
SophosQjMonkey (PUA)
F-SecureAdware.ADWARE/Qjwmonkey.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R01FC0PFC21
McAfee-GW-EditionArtemis!PUP
FireEyeGen:Variant.Application.Downloader.Nezchi.1
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Qjwmonkey.q
WebrootW32.Adware.Gen
AviraADWARE/Qjwmonkey.Gen
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASMalwS.3377E88
MicrosoftPUA:Win32/Qjwmonkey
GridinsoftTrojan.Qjwmonkey.dd!c
AegisLabAdware.Win32.Qjwmonkey.2!c
ZoneAlarmnot-a-virus:AdWare.Win32.Qjwmonkey.ejz
GDataGen:Variant.Application.Downloader.Nezchi.1
AhnLab-V3PUP/Win.Qjwmonkey.R425095
McAfeeArtemis!7145A179B496
MAXmalware (ai score=97)
VBA32BScope.Downloader.Agent
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R01FC0PFC21
RisingAdware.Downloader!1.BDCA (CLASSIC)
YandexPUA.Qjwmonkey!F8bevza9pP8
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Qjwmonkey.K
AVGWin32:WormX-gen [Wrm]
Paloaltogeneric.ml

How to remove AdWare.Win32.Qjwmonkey.ejz?

AdWare.Win32.Qjwmonkey.ejz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment