Malware

Application.Bundler.InstallMonster.392 removal guide

Malware Removal

The Application.Bundler.InstallMonster.392 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.InstallMonster.392 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Bundler.InstallMonster.392?


File Info:

name: 63AD5C260B9885C9ED70.mlw
path: /opt/CAPEv2/storage/binaries/5b803dee9d044226bbd0be349c45b1ff02362ae4dc089c82d13d3da08a54151f
crc32: 74D5A24B
md5: 63ad5c260b9885c9ed704ef781f84173
sha1: 95e529093559b8d78b263963ef80dcd7371461a6
sha256: 5b803dee9d044226bbd0be349c45b1ff02362ae4dc089c82d13d3da08a54151f
sha512: fe3c54cde136adc9264c02b5b1c260674b0150b5f0a50fd6312245af282bcc64bfeec1485957befce3ff0572690bd6e3c5a1014b5610e27c8da1f1558a89442b
ssdeep: 98304:i6hdchEV4pBgdfU4Io2y6eYuS6Ko8XhzC2LoBNx8J9Hx:NDchwe8fU4b6eRS3o8xwxK9R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157A6F113B5C5F63BC89F0A36566795214B3BAB0425258CD75EF1081CDF2A8C13AFB29B
sha3_384: 250852bf0771aa8a0d2856fc71f0bcdfc7ac0fff3ee823b9051f0df83dd26b0543d05279af6dab9e04e9c0980ca02323
ep_bytes: 558becb9050000006a006a004975f953
timestamp: 2018-03-15 11:18:16

Version Info:

0: [No Data]

Application.Bundler.InstallMonster.392 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.tpoW
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.63ad5c260b9885c9
CAT-QuickHealTrojan.Inject.A11
SkyhighBehavesLike.Win32.Generic.tt
McAfeeGenericRXEO-EX!63AD5C260B98
Cylanceunsafe
VIPREGen:Variant.Application.Bundler.InstallMonster.392
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/InstallMonstr.VV potentially unwanted
APEXMalicious
KasperskyTrojan.Win32.Inject.apthl
BitDefenderGen:Variant.Application.Bundler.InstallMonster.392
NANO-AntivirusTrojan.Win32.Inject.eyzqry
MicroWorld-eScanGen:Variant.Application.Bundler.InstallMonster.392
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10bfa9fe
TACHYONTrojan/W32.DP-Inject.9613824
SophosInstall Monster (PUA)
F-SecureAdware.ADWARE/InstMonster.Gen7
DrWebTrojan.InstallMonster.2801
ZillyaTrojan.Inject.Win32.246658
TrendMicroTROJ_GEN.R002C0PBT24
EmsisoftGen:Variant.Application.Bundler.InstallMonster.392 (B)
IkarusPUA.InstallMonstr.Up
JiangminTrojan.Inject.amsq
GoogleDetected
AviraADWARE/InstMonster.Gen7
Antiy-AVLTrojan/Win32.Inject
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumApplication.Win32.DLBoost.AA@7onrhs
ArcabitTrojan.Application.Bundler.InstallMonster.392
ViRobotTrojan.Win.Z.Inject.9613824.A
ZoneAlarmTrojan.Win32.Inject.apthl
GDataGen:Variant.Application.Bundler.InstallMonster.392
AhnLab-V3Trojan/Win.Generic.R465398
BitDefenderThetaGen:NN.ZelphiF.36802.@VX@aaUzpahc
ALYacGen:Variant.Application.Bundler.InstallMonster.392
MAXmalware (ai score=71)
VBA32Trojan.Inject
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PBT24
RisingPUF.InstallMonstr!8.EA (TFE:4:9xEeIpLC1aU)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Inject.aixeq
FortinetW32/Injector.CTWA!tr
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.60b988
DeepInstinctMALICIOUS

How to remove Application.Bundler.InstallMonster.392?

Application.Bundler.InstallMonster.392 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment