Adware

What is “Adware.BundleInstaller”?

Malware Removal

The Adware.BundleInstaller is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.BundleInstaller virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
down6.youtubemusicdownloader.us
down.youtubemusicdownloader.us

How to determine Adware.BundleInstaller?


File Info:

crc32: 97408FC2
md5: ee2e4adba3621c8c1190e6ba7df4ce79
name: EE2E4ADBA3621C8C1190E6BA7DF4CE79.mlw
sha1: 8403ca1d0d2a1ab2887f76b68a99b833cf0a6fb4
sha256: 2753dcf200ed88a8b191eecb25db809553892bf141c228e70b84479519fc8fcc
sha512: 7af242c2978a212eecb5b5b5bdf6360166198adc717c70fcfad3733237962f3d0c6b68a889d1dc1ef49410c7a89a0197e1cc73eba41402731db8fd8f809cdffe
ssdeep: 12288:BadLWD7888888888888W888888888887P7K/RRgoe4vygRNzRq7YAVkTijKdkBwB:UBWtDK/Re3mlqmuBYKq7I6Khyk0th
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 8.6.0.1
CompanyName: YoutubeDownloader.guru LLC.
Comments: This installation was built with Inno Setup.
ProductName: Youtube Video/Music Downloader
ProductVersion: 8.6
FileDescription: Youtube Video/Music Downloader Setup
Translation: 0x0000 0x04b0

Adware.BundleInstaller also known as:

MicroWorld-eScanTrojan.GenericKD.34935572
FireEyeTrojan.GenericKD.34935572
McAfeeArtemis!EE2E4ADBA362
MalwarebytesAdware.BundleInstaller
SUPERAntiSpywarePUP.InstallCore/Variant
SangforMalware
K7AntiVirusAdware ( 00551cbd1 )
BitDefenderTrojan.GenericKD.34935572
K7GWAdware ( 00551cbd1 )
Cybereasonmalicious.ba3621
APEXMalicious
Kasperskynot-a-virus:RiskTool.Win32.SystemCare.bsd
AlibabaRiskWare:Win32/SystemCare.38994c09
Ad-AwareTrojan.GenericKD.34935572
SophosYoutubeDownloaderGuru (PUA)
F-SecureHeuristic.HEUR/AGEN.1134885
DrWebAdware.Downware.17430
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
EmsisoftApplication.InstallShare (A)
WebrootPua.Downloadmanager
AviraHEUR/AGEN.1134885
MicrosoftPUA:Win32/CandyOpen
ArcabitTrojan.Generic.D2151314
AegisLabRiskware.Win32.SystemCare.1!c
ZoneAlarmnot-a-virus:RiskTool.Win32.SystemCare.bsd
GDataTrojan.GenericKD.34935572
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.BundleInstaller.R198323
ALYacTrojan.GenericKD.34935572
MAXmalware (ai score=99)
CylanceUnsafe
FortinetRiskware/SystemCare
AVGWin32:Adware-gen [Adw]
AvastWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Virus.RiskTool.2ba

How to remove Adware.BundleInstaller?

Adware.BundleInstaller removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment