Adware

Win32/Adware.Cjishu.G malicious file

Malware Removal

The Win32/Adware.Cjishu.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Cjishu.G virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Adware.Cjishu.G?


File Info:

name: C5E44C03843D1137439B.mlw
path: /opt/CAPEv2/storage/binaries/77fb15abb176771c97b53734aba9236d6907ad5333d943882984cfacbe550af2
crc32: D9FC4DCB
md5: c5e44c03843d1137439bea9f087e0a23
sha1: 0a81a47a6439ee488a149c3b9d37d1df1596e5c7
sha256: 77fb15abb176771c97b53734aba9236d6907ad5333d943882984cfacbe550af2
sha512: 84780916be6693d2bce56c8d2697486a78b095f01553af6bd50633c8085613e5c63ff52e29041a69e4fb43193a469c656bc33725cbb6c385e7faf61aa733a3c2
ssdeep: 24576:0LUoVJwLfpm9GbPYl5IguaHbX6HMfPoc7Qt/lCSYgfvRaxOpV6:Xfppk5zf7QtdrRa4V6
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1E435AF12FB8180B2E5DE02B462BA577B583DA924033985C3EBD46CE96D706C1B73E7D1
sha3_384: 79cde4ea69af2921f84a80276ea02bbd939eee4190da35dffeda20b1340339c13d7dbcb9e1b213edb2e11a023ac71a7a
ep_bytes: 558bec837d0c017505e8a4f80000ff75
timestamp: 2023-01-14 16:28:45

Version Info:

0: [No Data]

Win32/Adware.Cjishu.G also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Cjishu.2!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.c5e44c03843d1137
Cylanceunsafe
SangforAdware.Win32.Cjishu.Vfs2
K7AntiVirusAdware ( 005b14f81 )
K7GWAdware ( 005b14f81 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Cjishu.G
AvastWin32:AdwareX-gen [Adw]
F-SecureAdware.ADWARE/Cjishu.xdutn
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Cjishu
GDataWin32.Application.Agent.WKO4TK
AviraADWARE/Cjishu.xdutn
Antiy-AVLTrojan/Win32.Agent
Kingsoftwin32.troj.undef.a
MicrosoftPUA:Win32/Bitrepeyp.A
VBA32Adware.Cjishu
MalwarebytesPUP.Optional.ChinAd.DDS
RisingAdware.Cjishu!1.F557 (CLASSIC)
MaxSecureTrojan.Malware.216064600.susgen
FortinetRiskware/Cjishu
BitDefenderThetaGen:NN.ZedlaF.36744.gv5@aapafbni
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS

How to remove Win32/Adware.Cjishu.G?

Win32/Adware.Cjishu.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment