Adware

About “Adware:Win32/Cjishu.A” infection

Malware Removal

The Adware:Win32/Cjishu.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Cjishu.A virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a hidden or system file

Related domains:

lh.cjishu.com
lhoss.yx1999.com

How to determine Adware:Win32/Cjishu.A?


File Info:

crc32: FA89BA36
md5: 0ac9acf04d37e3e37d8fad5718a81216
name: 0AC9ACF04D37E3E37D8FAD5718A81216.mlw
sha1: 1873eb6c9ad10375ae8dc4abd4a3e99d7286dc2e
sha256: 40f5bccd118354c2d03f23faec5b4edd2d71926fd9b8dbaf6863ba9378ab13f5
sha512: aeec49029d419f14af5a4d23deb3877fc1313b9794540308f96a7bffa8bfd4a3fddd470927784b815f12e35f3aaafeb8f26a65c8129706d84728b77f60ba4019
ssdeep: 12288:x11pItmpSxQjOxMiWG4njkB2f756Wu+urQ9+nLf48mY5hrULTCAnr+MIfamMIsE:r1pItmpd/s7x3rLibIsEQsA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: Upgeader.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductVersion: 1.0.0.1
FileDescription: encrydata upgrader
OriginalFilename: Upgeader.exe
Translation: 0x0804 0x04b0

Adware:Win32/Cjishu.A also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Graftor.479668
AlibabaAdWare:Win32/Cjishu.129d5d48
Cybereasonmalicious.04d37e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Cjishu.B
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan.Win32.Invader
BitDefenderGen:Variant.Graftor.479668
MicroWorld-eScanGen:Variant.Graftor.479668
Ad-AwareGen:Variant.Graftor.479668
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.6u0@aq3zZ6cj
FireEyeGeneric.mg.0ac9acf04d37e3e3
EmsisoftGen:Variant.Graftor.479668 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1140217
MicrosoftAdware:Win32/Cjishu.A
GDataGen:Variant.Graftor.479668
AhnLab-V3Malware/Win32.Generic.C2798300
MAXmalware (ai score=85)
VBA32BScope.TrojanDropper.Dycler
MalwarebytesMalware.AI.2257820235
PandaTrj/Genetic.gen
RisingAdware.AdPop!1.B85F (CLASSIC)
IkarusPUA.Cjishu
AVGFileRepMalware

How to remove Adware:Win32/Cjishu.A?

Adware:Win32/Cjishu.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment