Malware

BrowserModifier:Win32/Qiwmonk removal instruction

Malware Removal

The BrowserModifier:Win32/Qiwmonk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BrowserModifier:Win32/Qiwmonk virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine BrowserModifier:Win32/Qiwmonk?


File Info:

crc32: 53B439B2
md5: 095b08a53bd5a40960f1b10972658fd3
name: wxhycssc_ppc.apk
sha1: e3ccd8cf9b4cb62ce69f7be6487f353141c21c52
sha256: 5325c753f3081b5e15ffb5ea109785cd344b2d3ec2b6e0d998da62bcc83156bf
sha512: 462f8950401cbf6fe366050e2c272173601d6c729b116520b3e3ec04885ab776bd5de8280a750e9e2f946577890d6de79991953b6886543d639dda16f96847b6
ssdeep: 24576:cEmkZQuSb1QIT/oDIuIDV9Qla+Mgd6lGGS/ondRNULjr2:cnCfqcODnvUCvS/MdRkjr2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 4.0.0.815
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 4.0.0.815
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

BrowserModifier:Win32/Qiwmonk also known as:

MicroWorld-eScanGen:Variant.Application.Razy.26615
CAT-QuickHealPUA.QjwmonkeyPMF.S7500555
McAfeeQJWMonkey
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 00510c5c1 )
BitDefenderGen:Variant.Application.Razy.26615
K7GWAdware ( 00510c5c1 )
Cybereasonmalicious.53bd5a
ArcabitTrojan.Application.Razy.D67F7
Invinceaheuristic
F-ProtW32/S-010eab50!Eldorado
SymantecPUA.Downloader
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
APEXMalicious
ClamAVWin.Malware.Razy-6998114-0
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
AlibabaAdWare:Win32/Qjwmonkey.0dd0aefc
NANO-AntivirusTrojan.Win32.Qjwmonkey.fwqdab
ViRobotAdware.Qjwmonkey.1447952.B
SUPERAntiSpywareTrojan.Agent/Gen-MalPack
TencentMalware.Win32.Gencirc.10b58732
Ad-AwareGen:Variant.Application.Razy.26615
EmsisoftGen:Variant.Application.Razy.26615 (B)
ComodoApplicUnwnt@#orcsq0x11stx
DrWebAdware.Qjwmonkey.161
ZillyaAdware.Qjwmonkey.Win32.529
TrendMicroPUA.Win32.QJWMonkey.GL
McAfee-GW-EditionQJWMonkey
FortinetW32/Qjwmonkey.D!tr
FireEyeGeneric.mg.095b08a53bd5a409
SophosQjMonkey (PUA)
IkarusPUA.Qjwmonkey
CyrenW32/Application.OOPW-5614
JiangminDownloader.Generic.aqxb
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1042852
MAXmalware (ai score=100)
Antiy-AVLGrayWare[Modifier]/Win32.Qiwmonk
Endgamemalicious (high confidence)
MicrosoftBrowserModifier:Win32/Qiwmonk
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Generic
AhnLab-V3PUP/Win32.RL_Qjwmonkey.R287544
Acronissuspicious
VBA32BScope.Adware.Qjwmonkey
PandaTrj/Genetic.gen
TrendMicro-HouseCallPUA.Win32.QJWMonkey.GL
RisingAdware.Downloader!1.B5B0 (CLASSIC)
YandexPUA.Downloader!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
GDataGen:Variant.Application.Razy.26615
AVGWin32:Adware-gen [Adw]
AvastWin32:Adware-gen [Adw]

How to remove BrowserModifier:Win32/Qiwmonk?

BrowserModifier:Win32/Qiwmonk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment