Malware

Win32:InstallCube-JS [Adw] removal instruction

Malware Removal

The Win32:InstallCube-JS [Adw] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:InstallCube-JS [Adw] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Exhibits behavior characteristic of iSpy Keylogger
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed analysis tools by registry key
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VMware through the presence of a registry key

How to determine Win32:InstallCube-JS [Adw]?


File Info:

crc32: 3D6459B4
md5: f37a2bb2b8208517e24c4d6736ae41c2
name: F37A2BB2B8208517E24C4D6736AE41C2.mlw
sha1: bd6d6b3f0398a3363dd9c9694c44ddbb945f227f
sha256: ddd0dfe80a6a9014665d1673a85e6f6b4c766455459ff2fdd7ad054e890d2bd4
sha512: 9f692ddf7441f500849eb0ca9d3f1a0a4cfe419ac47e23d7a88c4c35a17a6a86496c85ebbfc45a0afa34c7f275a878a83a13b5a9629249b45148c8e1b9a26b64
ssdeep: 12288:d0tL7hf3bvOBpXQUMMnW0Li7hf3bvOBpXgh5WV8d9i:dOpf3bOBpXlMMnW0Lef3bOBpXYe8u
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Fuckuim
Assembly Version: 4.123.0.0
InternalName: Wizzupdater.exe
FileVersion: 1.0.0.0
CompanyName: Nagatuim
LegalTrademarks:
Comments: Khanuim
ProductName: Terzium
ProductVersion: 1.0.0.0
FileDescription: Blqckuim
OriginalFilename: Wizzupdater.exe

Win32:InstallCube-JS [Adw] also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Application.Bundler.Temonde.1
FireEyeGeneric.mg.f37a2bb2b8208517
McAfeePUP-XCD-OF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 0054519c1 )
BitDefenderGen:Application.Bundler.Temonde.1
K7GWAdware ( 0054519c1 )
Cybereasonmalicious.2b8208
CyrenW32/S-2546838f!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:InstallCube-JS [Adw]
ClamAVWin.Adware.SpywareJarl-4
Kasperskynot-a-virus:HEUR:Downloader.MSIL.Temonde.gen
AlibabaDownloader:MSIL/Temonde.1ca685bc
NANO-AntivirusTrojan.Win32.Temonde.ebrjvc
ViRobotAdware.Temonde.1002496
AegisLabRiskware.MSIL.Generic.1!c
TencentMalware.Win32.Gencirc.10b37132
Ad-AwareGen:Application.Bundler.Temonde.1
SophosCsdiMonetize (PUA)
ComodoMalware@#1idedogl9ggxn
F-SecureHeuristic.HEUR/AGEN.1123816
DrWebAdware.Eorezo.814
ZillyaDownloader.Temonde.Win32.1081
TrendMicroTROJ_GEN.R002C0PB321
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftGen:Application.Bundler.Temonde.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.MSIL.ga
AviraHEUR/AGEN.1123816
Antiy-AVLRiskWare[Downloader]/MSIL.Temonde
MicrosoftSoftwareBundler:MSIL/Wizrem
GridinsoftAdware.Win32.Downloader.oa
ZoneAlarmnot-a-virus:HEUR:Downloader.MSIL.Temonde.gen
GDataGen:Application.Bundler.Temonde.1
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.BundleInstaller.R198869
BitDefenderThetaGen:NN.ZemsilF.34804.9m0@aadYDDf
ALYacGen:Application.Bundler.Temonde.1
MAXmalware (ai score=79)
VBA32TScope.Trojan.MSIL
MalwarebytesAdware.Tuto4PC
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Adware.CsdiMonetize.A
TrendMicro-HouseCallTROJ_GEN.R002C0PB321
RisingMalware.Wizrem!8.E94B (TFE:C:YX890hBxIKU)
YandexPUA.Downloader!p9rf8h1l+uE
IkarusAdWare.MSIL.Csdimonetize
FortinetRiskware/Temonde
AVGWin32:InstallCube-JS [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/Trojan.fa0

How to remove Win32:InstallCube-JS [Adw]?

Win32:InstallCube-JS [Adw] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment