Malware

Application.Bundler.InstallMonster.RK information

Malware Removal

The Application.Bundler.InstallMonster.RK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.InstallMonster.RK virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • Detects the presence of Wine emulator via function name
  • Queries information on disks, possibly for anti-virtualization
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects information about installed applications
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key

Related domains:

z.whorecord.xyz
a.tomx.xyz
redtop.credicial.ru
bestwizzards.life

How to determine Application.Bundler.InstallMonster.RK?


File Info:

crc32: D6697EAD
md5: cba0127cfc34d04a363d34c3c298cd79
name: CBA0127CFC34D04A363D34C3C298CD79.mlw
sha1: b16987db6de998595da2b2e4b533f2d67db46962
sha256: 1a383d048f9da2d964e07b9ac425274b9575620b209c6f5c99f42f3cfce9ad42
sha512: 719c3ce018e6821d2eb91636212bb2e4fb7362f70853716f4d02b40a6197e4e2e31987f05dd9b325d7f7b7df36d9fa20473b600604ed963985f6bd92092eab86
ssdeep: 49152:/0ENERTLleSd2ynuAjeatQji/+5tmx1AF7HdjXiC3c3bYJQJw5W/Tar8MDQ7X:/0qaSi/+5y1i79jygl5WrU8Mc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: xInternalName
FileVersion: 33.6.7.44
LegalTrademarks: xLegalTrademarks
Comments: xComments
ProductName: xProductName
ProgramID: xProgramID
ProductVersion: 1.2.4.54
FileDescription: xFileDescription
OriginalFilename: xOriginalFilename
Translation: 0x0488 0x04e4

Application.Bundler.InstallMonster.RK also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 004f3e551 )
LionicTrojan.Win32.Inject.4!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallMonster.2564
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Inject.A11
ALYacApplication.Bundler.InstallMonster.RK
CylanceUnsafe
ZillyaTool.Bundler.Win32.5278
SangforTrojan.Win32.Save.a
K7GWAdware ( 004f3e551 )
Cybereasonmalicious.cfc34d
CyrenW32/AdAgent.AX.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/InstallMonstr.QU potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyTrojan.Win32.Inject.aifxk
BitDefenderApplication.Bundler.InstallMonster.RK
NANO-AntivirusTrojan.Win32.Inject.expokw
MicroWorld-eScanApplication.Bundler.InstallMonster.RK
TencentMalware.Win32.Gencirc.10b4db00
Ad-AwareApplication.Bundler.InstallMonster.RK
SophosInstall Monster (PUA)
ComodoApplication.Win32.InstallMonster.HN@7jiloq
BitDefenderThetaGen:NN.ZelphiF.34236.@V1@ayoK5Wbk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vm
FireEyeGeneric.mg.cba0127cfc34d04a
EmsisoftApplication.Bundler.InstallMonster.RK (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.amcf
AviraADWARE/InstMonster.Gen7
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Inject
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmTrojan.Win32.Inject.aifxk
GDataApplication.Bundler.InstallMonster.RK
AhnLab-V3PUP/Win32.InstallMonster.R219813
Acronissuspicious
McAfeePUP-XDZ-RH
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesAdware.InstallMonster
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!tYm7zzC//4M
IkarusTrojan-Dropper
MaxSecureTrojan.Malware.11982220.susgen
FortinetW32/Injector.CTWA!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Application.Bundler.InstallMonster.RK?

Application.Bundler.InstallMonster.RK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment