Malware

Should I remove “Application.Bundler.InstallMonster.QF”?

Malware Removal

The Application.Bundler.InstallMonster.QF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.InstallMonster.QF virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Bundler.InstallMonster.QF?


File Info:

name: 805C950227F439291B61.mlw
path: /opt/CAPEv2/storage/binaries/70edbed7e14622fd8349b5268ad303e4889129f0a7a9cd74412b5025ec56d281
crc32: 01467638
md5: 805c950227f439291b6197dffa50fd01
sha1: 8368b4d3535b16e8278d110a7f7af5361f768c60
sha256: 70edbed7e14622fd8349b5268ad303e4889129f0a7a9cd74412b5025ec56d281
sha512: 2d2931c9be333a67721b0175e3fec7ebd1c67b6763a44669954fd8d5739ccf35d5f5abf3051e6b78da92b0d5adc13b98b278001dfa1addbe3079ad17f5fb405f
ssdeep: 98304:o91js9hb7Pp3KJR1sWItmIugLaYb+B86hNTfIJcg/E7J0epHJF0cm9biAg07R6dv:CjsjReR1sHtmILaYqjhIJcsCNBJF0JR0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C46334500E868BFD685A77AA70AFF94D1EFA51319AFC356366417C73D7A8C42B033A0
sha3_384: acfd65e05b4cbcf8525528cb9ca8cbeb6e6cbbd56ebac213449dd9f627935c4a9230098979d496e338726a4db0a001e5
ep_bytes: 60be007070018dbe00a07fff5783cdff
timestamp: 2017-12-27 13:19:47

Version Info:

InternalName: bdsrtnh
LegalCopyright: dsrtb
LegalTrademarks: swervsaer
OriginalFilename: hsaevg
ProductName: aewvrawe
ProductVersion: 555.454.5.75
Comments: nhwrnjsrytg
FileVersion: 776.667.665.281
Translation: 0x0451 0x0000

Application.Bundler.InstallMonster.QF also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.lVIb
Elasticmalicious (moderate confidence)
CAT-QuickHealTrojan.Resoric.ZZ8
SkyhighBehavesLike.Win32.IMonster.tc
ALYacApplication.Bundler.InstallMonster.QF
MalwarebytesAdware.InstallMonster
VIPREApplication.Bundler.InstallMonster.QF
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 0052cbe61 )
BitDefenderApplication.Bundler.InstallMonster.QF
K7GWAdware ( 0052cbe61 )
Cybereasonmalicious.227f43
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/InstallMonstr.QU potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.ahybv
NANO-AntivirusTrojan.Win32.Inject.ewmxqt
ViRobotAdware.Installmonster.5854208.FQ
MicroWorld-eScanApplication.Bundler.InstallMonster.QF
AvastWin32:Adware-gen [Adw]
RisingPUF.InstallMonstr!8.EA (TFE:5:0rF9BgKkAdR)
EmsisoftApplication.Bundler.InstallMonster.QF (B)
F-SecureAdware.ADWARE/InstMonster.Gen7
DrWebTrojan.InstallMonster.2517
ZillyaTool.Bundler.Win32.5175
TrendMicroTROJ_GEN.R002C0GBH24
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.805c950227f43929
SophosInstall Monster (PUA)
SentinelOneStatic AI – Suspicious PE
GDataApplication.Bundler.InstallMonster.QF
JiangminTrojan.Inject.adln
AviraADWARE/InstMonster.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Inject
KingsoftWin32.Trojan.Agent.gen
XcitiumApplication.Win32.InstallMonster.UB@7g9yow
ArcabitApplication.Bundler.InstallMonster.QF
ZoneAlarmTrojan.Win32.Inject.ahybv
MicrosoftSoftwareBundler:Win32/InstallMonster
VaristW32/InstallMonster.JH.gen!Eldorado
AhnLab-V3PUP/Win32.InstallMonster.R216687
McAfeeArtemis!805C950227F4
TACHYONTrojan/W32.DP-Inject.13605888
VBA32Trojan.Inject
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0GBH24
TencentMalware.Win32.Gencirc.10b1a0fa
IkarusPUA.InstallMonstr.Up
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CTWA!tr
BitDefenderThetaAI:Packer.FEB04CA521
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)
alibabacloudTrojan:Win/Mint

How to remove Application.Bundler.InstallMonster.QF?

Application.Bundler.InstallMonster.QF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment