Malware

MonitoringTool:Win32/Actmon removal guide

Malware Removal

The MonitoringTool:Win32/Actmon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MonitoringTool:Win32/Actmon virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for fileless persistence
  • A script process created a new process
  • Harvests cookies for information gathering

How to determine MonitoringTool:Win32/Actmon?


File Info:

name: 2FDC3036007181DCC4E7.mlw
path: /opt/CAPEv2/storage/binaries/174a9a48b8e8db2e83c1a72ef825d0e7ea6c7a504679857afcbe3b42d5460002
crc32: D952613E
md5: 2fdc3036007181dcc4e753a5b978363b
sha1: 84ec8d9788393de82f695ed6ab335997b3622fc1
sha256: 174a9a48b8e8db2e83c1a72ef825d0e7ea6c7a504679857afcbe3b42d5460002
sha512: 1556cff8b6906c9b681ab2cc2e743e5702f25327300902cc0e67616d7848eafe548dece80ba4cf9af3d74c69560a4999239835f1e6c43d0b637728261e7555b0
ssdeep: 12288:r5ZjyMFEWa76/wiH0FPt0YEchBnnJ9xYLdO1aBEHXkimaO35LxMK3VUhsBqj:1ZjyMg7AYDUchBnnhYxOUaO35LxMgVRq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEE41245B7C586F7D1814B70A86E9329F5BDFF112F38628D8B5D4C2C3C78A81A41BA63
sha3_384: 4e190b3618a22c7a8ec48d13c36736cb3207d6aea9e7b827e058e1f1276d4e38610661e709a9e828ebf385e7c635b043
ep_bytes: e8bf27000050e8272901000000000090
timestamp: 2006-03-28 19:23:00

Version Info:

0: [No Data]

MonitoringTool:Win32/Actmon also known as:

LionicWorm.VBS.Autorun.o!c
DrWebVBS.Autoruner.20
MicroWorld-eScanApplication.Tool.475
FireEyeApplication.Tool.475
CAT-QuickHealMonitoringTool.Actmon
McAfeeArtemis!2FDC30360071
CylanceUnsafe
VIPREActmon PC & Internet Monitoring
SangforWorm.VBS.Autorun.i
K7AntiVirusUnwanted-Program ( 00502c811 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWUnwanted-Program ( 00502c811 )
CyrenW32/Spyware.UVZJ-5096
SymantecTrojan.Dropper
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyWorm.VBS.Autorun.i
BitDefenderApplication.Tool.475
NANO-AntivirusRiskware.Win32.Actmon.btpet
AvastWin32:ActMon-E [PUP]
TencentVbs.Worm.Autorun.Hwnk
SophosW32/Isetspy-C
ComodoApplicUnsaf@#w4zylwxykff7
BaiduVBS.Worm.Small.f
TrendMicroSPYWARE_KEYL_ACTIVITYMONITOR
McAfee-GW-EditionSpyware-ActMon.d
EmsisoftApplication.Tool.475 (B)
IkarusTrojan.Win32.Fibmont
GDataApplication.Generic.210975
JiangminAdWare/ActMon.a
AviraADSPY/ActMon.D
Antiy-AVLTrojan/Generic.ASMalwS.87E932
KingsoftWin32.RiskWare.MonitorActMo.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitApplication.Tool.475
ViRobotTrojan.Win32.Z.Actmon.712704
MicrosoftMonitoringTool:Win32/Actmon
VBA32Win32.Trojan.Dropper.Heur
MAXmalware (ai score=81)
MalwarebytesMalware.AI.4268381952
TrendMicro-HouseCallSPYWARE_KEYL_ACTIVITYMONITOR
RisingWorm.Script.VBS.Autorun.c (CLASSIC)
YandexWorm.VBS.Autorun.ACN
SentinelOneStatic AI – Suspicious SFX
FortinetRiskware/ActMon
AVGWin32:ActMon-E [PUP]
Cybereasonmalicious.600718
PandaTrj/CI.A

How to remove MonitoringTool:Win32/Actmon?

MonitoringTool:Win32/Actmon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment