Malware

AdWare.Win32.Qjwmonkey.rp removal instruction

Malware Removal

The AdWare.Win32.Qjwmonkey.rp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Qjwmonkey.rp virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers

Related domains:

w.nanweng.cn

How to determine AdWare.Win32.Qjwmonkey.rp?


File Info:

crc32: D14F580E
md5: 94afd2f9f05a443d13c1e073fb80b604
name: 94AFD2F9F05A443D13C1E073FB80B604.mlw
sha1: 198934a510284b59705d5b7fbda87d1fc02f093f
sha256: 2b7397e87b120ccd8f1e2f54f852a09969f637cfe0696a5af7e0e9577322a41f
sha512: dfa6fac3098d34a0cea7fdd76f6153a673c77fb25e8b41d07a41fb197bc2d72e2a59947190432cba1d3746a2f4c0f5143d10b66c31727d203c201cc8108ae2d0
ssdeep: 12288:jLOx+2aSP7jpuixtUEjPSlk8Hf2T18021aGdumXcNpJbGslxkdO:jLylaG7HnOG18zfumqe6SdO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2021
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 6.0.0.0125
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
FileDescription: _
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

AdWare.Win32.Qjwmonkey.rp also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Downloader.Nezchi.1
McAfeeGenericRXAA-AA!94AFD2F9F05A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00510c5c1 )
BitDefenderGen:Variant.Application.Downloader.Nezchi.1
K7GWAdware ( 00510c5c1 )
Cybereasonmalicious.9f05a4
ArcabitTrojan.Application.Downloader.Nezchi.1
CyrenW32/Application.QPYW-8944
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Qjwmonkey.rp
AlibabaAdWare:Win32/Qjwmonkey.0fb74e35
NANO-AntivirusRiskware.Win32.Qjwmonkey.ilkvbe
ViRobotAdware.Qjwmonkey.643728.B
AvastWin32:AdwareX-gen [Adw]
RisingAdware.Downloader!1.BDCA (CLOUD)
Ad-AwareGen:Variant.Application.Downloader.Nezchi.1
SophosGeneric PUA BJ (PUA)
F-SecureAdware.ADWARE/Qjwmonkey.Gen
DrWebAdware.Qjwmonkey.168
ZillyaAdware.Qjwmonkey.Win32.774
TrendMicroTROJ_GEN.R002C0WBE21
McAfee-GW-EditionPUP-XNO-WY
FireEyeGen:Variant.Application.Downloader.Nezchi.1
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.Qjwmonkey.b
WebrootW32.Adware.Gen
AviraADWARE/Qjwmonkey.Gen
MAXmalware (ai score=72)
Antiy-AVLGrayWare[AdWare]/Win32.Qjwmonkey
GridinsoftTrojan.Qjwmonkey.dd!c
MicrosoftPUA:Win32/Qjwmonkey
ZoneAlarmnot-a-virus:AdWare.Win32.Qjwmonkey.rp
GDataGen:Variant.Application.Downloader.Nezchi.1
CynetMalicious (score: 85)
AhnLab-V3Malware/Gen.RL_Reputation.R365195
ALYacGen:Variant.Application.Downloader.Nezchi.1
VBA32BScope.Downloader.Agent
MalwarebytesGeneric.Trojan.Malicious.DDS
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R06CH07B621
YandexPUA.Qjwmonkey!OsM7bwh0r0E
IkarusTrojan.Taranis
eGambitTrojan.Generic
FortinetRiskware/Generic_PUA_DB
AVGWin32:AdwareX-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove AdWare.Win32.Qjwmonkey.rp?

AdWare.Win32.Qjwmonkey.rp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment