Malware

What is “Application.Bundler.AVD”?

Malware Removal

The Application.Bundler.AVD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.AVD virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects the presence of Wine emulator via function name
  • Queries information on disks, possibly for anti-virtualization
  • Collects information about installed applications
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key

Related domains:

z.whorecord.xyz
a.tomx.xyz
rove.deteroin.ru
vita.hazardle.ru

How to determine Application.Bundler.AVD?


File Info:

crc32: 5E771442
md5: 626b01c76316bf451052733251a9f617
name: 626B01C76316BF451052733251A9F617.mlw
sha1: c20a26a2ac10ee8e93724022bd9620885a03164e
sha256: 1a4cf72b8fa3068f6713b3f6247f8998bb752590016476906b3e5e5f002da005
sha512: e9f99bf7dbd9665beb27f715ea4cd4434f5346c2c07ea11984a03e9fc57f5387d7819295fdcbeafdb33c8796bb757c24df3ffbb9ada4fed95b0ea9b5eac00dc8
ssdeep: 49152:9rQEaMDySmKae4Cfmpw6y5E+iK1BwkTcBqArc+10O++oasfsEI6+YB4pai9TWWX4:9cCmaE+ZJIzrMpfsp6aaiwgH/WIzrMX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Application.Bundler.AVD also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad4.4462
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Inject.A11
ALYacApplication.Bundler.AVD
CylanceUnsafe
ZillyaTool.Bundler.Win32.5485
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.76316b
CyrenW32/S-4202940b!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/InstallMonstr.VQ potentially unwanted
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyTrojan.Win32.Inject.aipvf
BitDefenderApplication.Bundler.AVD
NANO-AntivirusTrojan.Win32.Inject.eyfuyx
MicroWorld-eScanApplication.Bundler.AVD
TencentMalware.Win32.Gencirc.10b15c93
Ad-AwareApplication.Bundler.AVD
SophosInstall Monster (PUA)
ComodoApplication.Win32.InstallMonster.HN@7jiloq
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.626b01c76316bf45
EmsisoftApplication.Bundler.AVD (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.amfh
AviraADWARE/InstMonster.Gen7
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.249F071
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmTrojan.Win32.Inject.aipvf
GDataApplication.Bundler.AVD
TACHYONTrojan/W32.DP-Inject.6360064
AhnLab-V3PUP/Win32.InstallMonster.R220935
Acronissuspicious
McAfeeGenericRXDZ-FQ!626B01C76316
MAXmalware (ai score=99)
VBA32Trojan.Inject
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.80 (RDML:JlbJv0GFHCZyuKsTS2To8g)
YandexPUA.DLBoost!miButhFwS1Q
IkarusPUA.Installmonstr
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CTWA!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove Application.Bundler.AVD?

Application.Bundler.AVD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment