Malware

About “Application.InstallMonster.FX” infection

Malware Removal

The Application.InstallMonster.FX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.InstallMonster.FX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.InstallMonster.FX?


File Info:

name: B421FBF43360B10A4744.mlw
path: /opt/CAPEv2/storage/binaries/70d0f9ef62ae2b24fbe131cbec35c54b72273a8479364f3379245cf821bce092
crc32: 1B850D18
md5: b421fbf43360b10a47440afc3de726a5
sha1: 9249c8aaf21249450a8b8007dbfab7966680262b
sha256: 70d0f9ef62ae2b24fbe131cbec35c54b72273a8479364f3379245cf821bce092
sha512: d589007cf6de8ffd861e9d58d39cfd3b1e9d4e2c2c8eb5197e51c6d89cc697ccc192cc29fdf5d1d38cd36901c81a446d940d5351aaca6f9f370ce34e578568a3
ssdeep: 12288:ENNVnmY6w+UDTL2gNojZTYdNyoFa57bhInlmEk7AB3KlFPW+CmB9v:ENNwY6WxNojZcryoFaFaMh7EiUFs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BBC51227B6809971F4741A3938F2C398897EFC6129259E5FAE6175AA0F305C07D21F2F
sha3_384: 77a21f0ba7a692c8071d5164bc3f2d19ca66eea9b1557eb232722f0542821d759573e6de7af90b2e6860fa8306afc3e1
ep_bytes: e890030000e98efeffff558bec6a00ff
timestamp: 2018-05-15 14:03:29

Version Info:

FileVersion: 1.0.0.3
InternalName: Template.exe
LegalCopyright: Copyright (C) 2018
OriginalFilename: Template.exe
ProductVersion: 1.3.0.1
Translation: 0x0419 0x04b0

Application.InstallMonster.FX also known as:

LionicTrojan.Win32.InstallMonster.4!c
Elasticmalicious (high confidence)
DrWebTrojan.SkypeSpam.11070
MicroWorld-eScanApplication.InstallMonster.FX
FireEyeGeneric.mg.b421fbf43360b10a
CAT-QuickHealSWB.Prepscram.J5
SkyhighBehavesLike.Win32.Generic.vz
McAfeeGenericRXFK-PH!B421FBF43360
Cylanceunsafe
ZillyaAdware.Generic.Win32.60812
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005319091 )
AlibabaAdWare:Win32/Kryptik.0314367f
K7GWTrojan ( 005319091 )
BitDefenderThetaGen:NN.ZexaF.36744.NA0@ai7R9Ibk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HPNR
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderApplication.InstallMonster.FX
NANO-AntivirusTrojan.Win32.Chapak.fbwqie
AvastWin32:AdwareX-gen [Adw]
TencentMalware.Win32.Gencirc.10b0faca
EmsisoftApplication.InstallMonster.FX (B)
F-SecureHeuristic.HEUR/AGEN.1310301
VIPREApplication.InstallMonster.FX
TrendMicroTROJ_GEN.R002C0PB624
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Agent
GDataApplication.InstallMonster.FX
JiangminTrojan.Chapak.iq
WebrootPua.Adware.Gen
GoogleDetected
AviraHEUR/AGEN.1310301
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Trojan.Chapak.gen
XcitiumApplication.Win32.IStartSurf.PS@8c4m91
ArcabitApplication.InstallMonster.FX
ZoneAlarmHEUR:Trojan.Win32.Chapak.gen
MicrosoftSoftwareBundler:Win32/Prepscram
VaristW32/S-3e511c68!Eldorado
AhnLab-V3PUP/Win32.InstallMonster.R228258
VBA32BScope.Trojan.Chapak
ALYacApplication.InstallMonster.FX
MAXmalware (ai score=100)
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PB624
RisingTrojan.Kryptik!1.B236 (CLASSIC)
YandexTrojan.GenAsa!QdUQCzIuU44
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.12118273.susgen
FortinetW32/Kryptik.GFGF!tr
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Application.InstallMonster.FX?

Application.InstallMonster.FX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment