Malware

About “Application.Monitortool.BH” infection

Malware Removal

The Application.Monitortool.BH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Monitortool.BH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Application.Monitortool.BH?


File Info:

name: 26E73104CDE6FFC5976C.mlw
path: /opt/CAPEv2/storage/binaries/b802678894647bdef3eea6bf41351b3db7c1cdab4cbc878c400ceba34a88cf5e
crc32: BDEA1707
md5: 26e73104cde6ffc5976c5ae39e4166f3
sha1: 7de83d945742653e0f50a885cf2462aa2c54bc8b
sha256: b802678894647bdef3eea6bf41351b3db7c1cdab4cbc878c400ceba34a88cf5e
sha512: 08baad1a5e92faeeac60b5e0f1a8bed83f9b685af4bd25a27d514424f217240248fd451dbbb8ad58aa3dcbad4d0bf8d4b7b573b632a280237430a9da801949be
ssdeep: 98304:t+5syMIqLxpsQNxVN+5dNFZFeZnGFsz1opn5Wx1LYdg/ZhnK4MJl1:t++yMBx+QfjIrVeZGFN15W7k+jnE1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169363370E7A7917DC069457DDC0A662117ABFF17AFB0964932FCBD9E0B626C28F84081
sha3_384: d5a562085b3044ce6e37f98d251577559e3b13dc169f04a10b772468cd384bac7e49acd1de601d6d60a1641721eb2a46
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: 此安装程序由 Inno Setup 构建。
CompanyName: Keylogger Spy Monitor,Inc.
FileDescription: LAN Employee Monitor Setup
FileVersion: 4.32
LegalCopyright:
ProductName: LAN Employee Monitor
ProductVersion: 4.32
Translation: 0x0804 0x0000

Application.Monitortool.BH also known as:

LionicTrojan.Win32.Monitor.4!c
MicroWorld-eScanApplication.Monitortool.BH
FireEyeApplication.Monitortool.BH
CylanceUnsafe
ZillyaAdware.StartPage.Win32.125
SangforPUP.Win32.Vigua.A
K7AntiVirusTrojan ( 005643641 )
AlibabaMonitor:Win32/Spyware.a58fdd5b
K7GWTrojan ( 005643641 )
Cybereasonmalicious.4cde6f
CyrenW32/Trojan.KCXO-8225
SymantecSpyware.KGBSpy
ESET-NOD32a variant of Win32/Monitor.Myss.A
APEXMalicious
BitDefenderApplication.Monitortool.BH
EmsisoftApplication.KeyLogger (A)
SophosGeneric PUA HN (PUA)
Antiy-AVLTrojan/Generic.ASMalwS.31A2F6F
MicrosoftPUA:Win32/Vigua.A
GDataApplication.Monitortool.BH
ALYacApplication.Monitortool.BH
MAXmalware (ai score=83)
MalwarebytesPUP.Optional.KeyLogger
FortinetRiskware/Myss
WebrootSystem.Monitor.Computer.Spy.Mon

How to remove Application.Monitortool.BH?

Application.Monitortool.BH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment