Malware

How to remove “AdWare.Win32.InstallMonster.jjsq”?

Malware Removal

The AdWare.Win32.InstallMonster.jjsq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.InstallMonster.jjsq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine AdWare.Win32.InstallMonster.jjsq?


File Info:

name: DB96E3162F489B2FECDA.mlw
path: /opt/CAPEv2/storage/binaries/df4dc55294e854b515f39c4ad348dc39593b7cb40dec0007c27ec65a67e22844
crc32: 0CDF4EA4
md5: db96e3162f489b2fecda7367fa26e752
sha1: 037def584ea45eaae0db0b72bdeb5d446e00443e
sha256: df4dc55294e854b515f39c4ad348dc39593b7cb40dec0007c27ec65a67e22844
sha512: add7ed0c6cd2c8d1a3d6722014b5d5d8a19f29b7b9fd1a418ceda97a114eacd5c797f062da53efeec4a9dca6f30ddc291945cf0e0a057e592d18805411462e49
ssdeep: 49152:++fqwp1WnGoOHKHImd8QDUZiFA4EskwDOON1F/TzZbiWBrVMkR83:++fZWnj7HIm+mVS4PnLTF/xbiWBrVMkU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15EC533F27EC2087BDEEB9178876E3E64CCB518251E91124343C89DE03D689A3D52B75B
sha3_384: fee82f2153786497c322c0a7f9c4d996d9471b74182650db35c901361a9823d0d19ef7ddd75ad5f051a213cdd11920e2
ep_bytes: 558bec6aff6888c8420068c08c420064
timestamp: 2010-07-31 14:32:56

Version Info:

0: [No Data]

AdWare.Win32.InstallMonster.jjsq also known as:

CylanceUnsafe
SangforAdware.Win32.InstallMonster.jjsq
AlibabaAdWare:Win32/InstallMonetizer.2bb08e12
CyrenW32/S-f708394f!Eldorado
SymantecPUA.Gen.2
ESET-NOD32Win32/InstallMonetizer.AQ potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CK421
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.InstallMonster.jjsq
AvastFileRepMetagen [PUP]
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUP.vc
SophosGeneric PUA AD (PUA)
MaxSecureWin.MxResIcn.Heur.Gen
MAXmalware (ai score=99)
MicrosoftSoftwareBundler:Win32/Stallmonitz
CynetMalicious (score: 100)
McAfeeArtemis!DB96E3162F48
VBA32AdWare.InstallMonster
MalwarebytesMalware.AI.1192352467
FortinetAdware/InstallMonster
AVGFileRepMetagen [PUP]

How to remove AdWare.Win32.InstallMonster.jjsq?

AdWare.Win32.InstallMonster.jjsq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment