Malware

Win32/InstallMonstr.VN potentially unwanted removal guide

Malware Removal

The Win32/InstallMonstr.VN potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/InstallMonstr.VN potentially unwanted virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/InstallMonstr.VN potentially unwanted?


File Info:

name: F2A90D9B11603E24604E.mlw
path: /opt/CAPEv2/storage/binaries/963e8db2e0d6cef518ffb806f51758fbdb3207a5e0110daec368711becf47eb7
crc32: D5E1E478
md5: f2a90d9b11603e24604ecba7c0b3cec3
sha1: 6a3795e554da0678750a55bc40595e60024d44eb
sha256: 963e8db2e0d6cef518ffb806f51758fbdb3207a5e0110daec368711becf47eb7
sha512: aac0324a62de8c5665f9df0d36b2f9bb6a3bf4f9875f0a2168b3d5792a7b36df62585f233e5754c70e8f728c38b699beb0d54c5564ac575bcfca496631f69821
ssdeep: 49152:QIPl+7K3KbdSSDtIXEBGnqK7/qb+WYCYa8TyKfm8yN6eeUdCII9WWMe/sSDRi9SN:rPl+aRVTqSrxTffgTd96Xe4Uk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE76D123B100A73FC8DA463A5E2657275B7E5B56151D8CCA56F0084CCFBECC2266EAC7
sha3_384: 2473e45fe3361a3395fe9fce3c0b82299332230afa1318ab763816261f8324e427b98ba1ae38805f260f99c8f56f22d2
ep_bytes: 558bec83c4f0535657b85c830f01e8ad
timestamp: 2018-02-03 16:12:50

Version Info:

LegalTrademarks: xLegalTrademarks
OriginalFilename: xOriginalFilename
ProductName: xProductName
ProductVersion: 1.2.4.54
Comments: xComments
FileVersion: 33.6.7.78
ProgramID: xProgramID
FileDescription: xFileDescription
Translation: 0x0408 0x04e5

Win32/InstallMonstr.VN potentially unwanted also known as:

LionicTrojan.Win32.Inject.1b!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.Bundler.InstallMonster.397
FireEyeGeneric.mg.f2a90d9b11603e24
CAT-QuickHealTrojan.Inject.A11
SkyhighBehavesLike.Win32.Generic.vm
McAfeePUP-XDZ-RH
Cylanceunsafe
ZillyaTrojan.Inject.Win32.255588
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00529c641 )
K7GWAdware ( 00529c641 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZelphiF.36802.@V1@a0oVlsfi
SymantecAdware.GAIN
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/InstallMonstr.VN potentially unwanted
APEXMalicious
KasperskyTrojan.Win32.Inject.aifzg
BitDefenderGen:Variant.Application.Bundler.InstallMonster.397
NANO-AntivirusTrojan.Win32.Inject.exqhbi
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b0b3a0
TACHYONTrojan/W32.DP-Inject.7310848
SophosInstall Monster (PUA)
F-SecureAdware.ADWARE/InstMonster.Gen7
DrWebTrojan.InstallMonster.2574
VIPREGen:Variant.Application.Bundler.InstallMonster.397
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Application.Bundler.InstallMonster.397 (B)
IkarusPUA.InstallMonstr.Up
JiangminTrojan.Inject.ambr
ALYacGen:Variant.Application.Bundler.InstallMonster.397
WebrootW32.Adware.Gen
VaristW32/AdAgent.AX.gen!Eldorado
AviraADWARE/InstMonster.Gen7
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Trojan.Inject.aifzg
MicrosoftSoftwareBundler:Win32/InstallMonster
XcitiumApplication.Win32.InstallMonster.HN@7jiloq
ArcabitTrojan.Application.Bundler.InstallMonster.397
ViRobotAdware.Installmonstr.7310848.D
ZoneAlarmTrojan.Win32.Inject.aifzg
GDataGen:Variant.Application.Bundler.InstallMonster.397
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.InstallMonster.R219789
VBA32TScope.Trojan.Delf
GoogleDetected
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingPUF.InstallMonstr!8.EA (TFE:5:FUL5bOnz4eN)
YandexTrojan.GenAsa!gM7pS9nIXVI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CTWA!tr
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.b11603
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/InstallMonster

How to remove Win32/InstallMonstr.VN potentially unwanted?

Win32/InstallMonstr.VN potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment