Malware

About “Application.Bundler.ATQ” infection

Malware Removal

The Application.Bundler.ATQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.ATQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Application.Bundler.ATQ?


File Info:

name: 8C5066A55DA7497EBEEF.mlw
path: /opt/CAPEv2/storage/binaries/cb604bbbf956faddd275830f53b20e67ee30b5a480cfccd640bfdf582f953069
crc32: 9177B2CD
md5: 8c5066a55da7497ebeef1cf664f66635
sha1: a4b9310edd69eadc94ae8be1fa36ff066b38c169
sha256: cb604bbbf956faddd275830f53b20e67ee30b5a480cfccd640bfdf582f953069
sha512: 949aecbffa0a0d7f5760c77d4b9b094a0856e5b8089d9f173014db596567be2ad5433c0cb3163da52f2f5403904137d346620f13e373c2c152e2df256a8c4409
ssdeep: 12288:EeAs/Wuzupz7H7hwsBhOg12c8sWOAiTN4f3rd8YqkjjGSXII7KQlWZ:FAseuzuJbhlD2fiJu3rCkjjpIGKN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T125B5E3CCEC707CDDC2AE273CC6857568A094EC3B4D48265AD948730946FB8BE95BB439
sha3_384: 2e84bfac501508a6b73f5333f27120fca2d8db06001087b2a819152e7b6300ac44632f202c99dbd622c117a4e59e8117
ep_bytes: e8e2060000e987feffff558beca17030
timestamp: 2018-01-14 11:06:05

Version Info:

0: [No Data]

Application.Bundler.ATQ also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Generic.2!c
tehtrisGeneric.Malware
DrWebTrojan.Vittalia.13656
MicroWorld-eScanApplication.Bundler.ATQ
FireEyeGeneric.mg.8c5066a55da7497e
CAT-QuickHealSoftwareBundler.Prepscram.C7
McAfeePUP-XDT-CD
Cylanceunsafe
ZillyaAdware.StartSurf.Win32.36732
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00528e801 )
AlibabaAdWare:Win32/StartSurf.10957432
K7GWTrojan ( 00523cda1 )
ArcabitApplication.Bundler.ATQ
BitDefenderThetaGen:NN.ZexaF.36680.nAW@aO4X80ii
VirITTrojan.Win32.Vittalia.UFG
SymantecAdware.IstartSurf
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HPOQ
CynetMalicious (score: 100)
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderApplication.Bundler.ATQ
NANO-AntivirusRiskware.Win32.StartSurf.ewztzr
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b27dbb
SophosGeneric Reputation PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1317715
VIPREApplication.Bundler.ATQ
EmsisoftApplication.Generic (A)
IkarusTrojan.Kryptik
JiangminAdWare.StartSurf.alr
WebrootW32.Adware.Gen
VaristW32/S-8e05f954!Eldorado
AviraHEUR/AGEN.1317715
Antiy-AVLGrayWare[AdWare]/Win32.StartSurf
XcitiumApplication.Win32.IStartSurf.BS@7lng48
MicrosoftSoftwareBundler:Win32/Prepscram
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataApplication.Bundler.ATQ
GoogleDetected
AhnLab-V3PUP/Win32.StartSurf.R218095
VBA32BScope.AdWare.StartSurf
ALYacApplication.Bundler.ATQ
MAXmalware (ai score=97)
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA5 (CLASSIC)
YandexTrojan.GenAsa!v5YC+rmfqTc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FWQG!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (W)

How to remove Application.Bundler.ATQ?

Application.Bundler.ATQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment