Home Malware Programs Adware Monarimo

Monarimo

Posted: December 18, 2013

Threat Metric

Ranking: 13,358
Threat Level: 2/10
Infected PCs: 1,192
First Seen: December 18, 2013
Last Seen: September 28, 2023
OS(es) Affected: Windows

Monarimo Screenshot 1Monarimo is adware that may display a variety of pop-up random ads while computer users are browsing the Web. Monarimo affects Internet Explorer, Mozilla Firefox and Google Chrome web browsers. Monarimo may alter browser settings and interrupt into every Internet session of the Web user. Monarimo may lead to forced browser redirects to suspicious websites in order to boost website traffic and advertise numerous products and services; this might be the main goal of Monarimo. Monarimo may also gather and record information about the computer user's browsing routine. Commonly, Monarimo may enter the computer via bundled free software that computer users download from the Internet. Monarimo may also attempt to trick the computer user into thinking it is a genuine app that the PC user needs to perform certain online activities. The Monarimo advertisements may be used to generate advertising revenue from clicks on ads.

Monarimo Screenshot 2

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\monarimo\updatemonarimo.exe File name: updatemonarimo.exe
Size: 66.84 KB (66848 bytes)
MD5: a642295841d714170b8462055c9f1ca9
Detection count: 173
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\monarimo
Group: Malware file
Last Updated: January 2, 2014
C:\BACKUP\lorao\AppData\Local\Temp\LIL375A.tmp\MonarimoSetup.exe File name: MonarimoSetup.exe
Size: 231.78 KB (231784 bytes)
MD5: 3c37800d0b18ce320e964650dcf7bf67
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\BACKUP\lorao\AppData\Local\Temp\LIL375A.tmp\MonarimoSetup.exe
Group: Malware file
Last Updated: September 24, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{06BBCAF3-6B7B-424E-9CE8-E245B46D8760}{442B7D0B-8A9A-4BCF-8E22-8450AA820010}{8f98655c-be52-4581-86a8-732a883ba2ee}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{8F98655C-BE52-4581-86A8-732A883BA2EE}SOFTWARE\Microsoft\Tracing\monarimo_RASAPI32SOFTWARE\Microsoft\Tracing\monarimo_RASMANCSSOFTWARE\Microsoft\Tracing\updatemonarimo_RASAPI32SOFTWARE\Microsoft\Tracing\updatemonarimo_RASMANCSSoftware\monarimoSOFTWARE\Wow6432Node\Microsoft\Tracing\monarimo_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\monarimo_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updatemonarimo_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatemonarimo_RASMANCSSOFTWARE\Wow6432Node\monarimoSYSTEM\ControlSet001\services\eventlog\Application\Update monarimoSYSTEM\ControlSet001\services\Update monarimoSYSTEM\CurrentControlSet\services\eventlog\Application\Update monarimoSYSTEM\CurrentControlSet\services\Update monarimoHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}monarimo

Additional Information

The following directories were created:
%ProgramFiles%\monarimo%ProgramFiles(x86)%\monarimo
The following URL's were detected:
monarimo
Loading...