Home Malware Programs Adware App Bud

App Bud

Posted: July 28, 2014

Threat Metric

Ranking: 14,810
Threat Level: 2/10
Infected PCs: 2,829
First Seen: July 28, 2014
Last Seen: September 18, 2023
OS(es) Affected: Windows


App Bud is an adware application that may load several advertisements usually generated from a third party ad network. The random App Bud ads may be ones that come in the form of a pop-up or banner. In either case, use of the App Bud ads may redirect your web browser to other sites where it could have pages that attempt to aggressively offer other services or products through the internet. App Bud ads may reduce the performance of your web browser in some cases limiting your usage of media intensive pages. Stopping the App Bud ads from rendering on your screen, mostly when surfing the internet, make require finding and removing each component or plugin related to App Bud within your system. Automatically removing App Bud from your system may be done through the use of an antimalware application.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\App Bud\bin\AppBud.BrowserAdapter.exe File name: AppBud.BrowserAdapter.exe
Size: 96.53 KB (96536 bytes)
MD5: 1f5aad06d157b1c4d7cb4e2169df1d27
Detection count: 152
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\App Bud\bin
Group: Malware file
Last Updated: July 28, 2014
%PROGRAMFILES(x86)%\App Bud\bin\AppBud.PurBrowse64.exe File name: AppBud.PurBrowse64.exe
Size: 287 KB (287000 bytes)
MD5: 13b9da6a58402225fe101b108b3117c1
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\App Bud\bin
Group: Malware file
Last Updated: July 28, 2014
%PROGRAMFILES(x86)%\App Bud\bin\AppBud.PurBrowse64.exe File name: AppBud.PurBrowse64.exe
Size: 287 KB (287000 bytes)
MD5: 136ef35fd6272f696842b03a0d31ddc7
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\App Bud\bin
Group: Malware file
Last Updated: July 28, 2014
%TEMP%\App Bud\AppBud_Setup.exe File name: AppBud_Setup.exe
Size: 2.13 MB (2130488 bytes)
MD5: 3d3ae58db54323973cbd62fcc7460baf
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\App Bud
Group: Malware file
Last Updated: August 17, 2022
%PROGRAMFILES(x86)%\App Bud\AppBud.FirstRun.exe File name: AppBud.FirstRun.exe
Size: 1.12 MB (1123608 bytes)
MD5: e055789a9e3c940dbabbdac9a81dbcfb
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\App Bud
Group: Malware file
Last Updated: July 28, 2014

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\App BudSoftware\Microsoft\Internet Explorer\Approved Extensions\{F1DE8EC2-8502-46F5-83B6-23784216D364}SOFTWARE\Microsoft\Tracing\AppBud_RASAPI32SOFTWARE\Microsoft\Tracing\AppBud_RASMANCSSOFTWARE\Microsoft\Tracing\updateAppBud_RASAPI32SOFTWARE\Microsoft\Tracing\updateAppBud_RASMANCSSOFTWARE\Wow6432Node\App BudSOFTWARE\Wow6432Node\Microsoft\Tracing\AppBud_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\AppBud_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateAppBud_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateAppBud_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update App BudSYSTEM\ControlSet001\services\Update App BudSYSTEM\ControlSet002\services\eventlog\Application\Update App BudSYSTEM\ControlSet002\services\Update App BudSYSTEM\CurrentControlSet\services\eventlog\Application\Update App BudSYSTEM\CurrentControlSet\services\Update App BudHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}App Bud

Additional Information

The following directories were created:
%PROGRAMFILES%\App Bud%PROGRAMFILES(x86)%\App Bud%Temp%\App Bud
The following URL's were detected:
appbud.net
Loading...