Adware

Win32/Adware.Cjishu.G removal instruction

Malware Removal

The Win32/Adware.Cjishu.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Cjishu.G virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Adware.Cjishu.G?


File Info:

name: A8951C40A669E5D41B98.mlw
path: /opt/CAPEv2/storage/binaries/6b367d190f3ae7e097756b7ad7bb09695609ca60b63546678f8fb9e3e11f5ef8
crc32: 7E2D650C
md5: a8951c40a669e5d41b989eb7148b1dae
sha1: 60456aa25911040acb3c097c81ce507ef9958b80
sha256: 6b367d190f3ae7e097756b7ad7bb09695609ca60b63546678f8fb9e3e11f5ef8
sha512: 53a60bf5688daaac80f08dbcaa392fa60fd5f285493a4ecc1bc1c6e3bf0aadd629b027df7e31e7ddd549d8ca0971e0fd0d9ac411cc6a4d75e869d3a4946b3519
ssdeep: 24576:0LUoVJwLfpm9GbPYl5IguaHbX6HMfPoc7Qt/lCSYgfvRaxOpVI:Xfppk5zf7QtdrRa4VI
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T18035AF12FB8180B2E5DE02B462BA577B583DA924033985C3EBD46CE96D706C1B73E7D1
sha3_384: 8e032b434973672a8a7500c568310c19f418d94254eba11f7a4cc7d4b42b1bb69f02e315af0e89b56c04ac8e37c37abe
ep_bytes: 558bec837d0c017505e8a4f80000ff75
timestamp: 2023-01-14 16:28:45

Version Info:

0: [No Data]

Win32/Adware.Cjishu.G also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Cjishu.2!c
ClamAVWin.Packed.Gandcrab-6520432-4
FireEyeGeneric.mg.a8951c40a669e5d4
Cylanceunsafe
SangforAdware.Win32.Cjishu.Vupw
CrowdStrikewin/malicious_confidence_60% (W)
K7GWAdware ( 005b14f81 )
K7AntiVirusAdware ( 005b14f81 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Cjishu.G
CynetMalicious (score: 100)
AvastWin32:AdwareX-gen [Adw]
F-SecureAdware.ADWARE/Cjishu.ubzhj
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Cjishu
GDataWin32.Application.Agent.O3C4TF
AviraADWARE/Cjishu.ubzhj
Antiy-AVLTrojan/Win32.Agent
Kingsoftwin32.troj.undef.a
MicrosoftPUA:Win32/Bitrepeyp.A
VBA32Adware.Cjishu
MalwarebytesPUP.Optional.ChinAd.DDS
RisingAdware.Cjishu!1.F557 (CLASSIC)
MaxSecureTrojan.Malware.216064600.susgen
FortinetRiskware/Cjishu
BitDefenderThetaGen:NN.ZedlaF.36744.gv5@aapafbni
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS

How to remove Win32/Adware.Cjishu.G?

Win32/Adware.Cjishu.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment