Malware

Application.Bundler.228 (file analysis)

Malware Removal

The Application.Bundler.228 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.228 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Application.Bundler.228?


File Info:

crc32: EB0BA7D5
md5: a3ec49e2f14205c74b48277ba8475c6d
name: A3EC49E2F14205C74B48277BA8475C6D.mlw
sha1: fc3eb9436dc42dc686cba5f304db57a2bb393f55
sha256: 2487caf8801c86b52ab6aab0cfb48e50a8dc73da0b101a4ab73380678fcca09b
sha512: 06b8b8b6c72e2c58662e11ca5421fc425381a14a9859e3549e51ac9452251b11cf0aaae447c90372ffa13af00ea446512845f0b5ed639f36f21df6beba30df78
ssdeep: 12288:JdBJRp52F1m6n8acnZdUCmf22EH3LrT0dTT2Eo1HyYD6ubqtJ0aXHkd3c:bBJNuEpaUufKbrTCTfo1H1D6ubqHr0ds
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Shanghai Janaei Network Technology Co., Ltd.
FileVersion: 2018.906.1734.2
CompanyName: Shanghai Janaei Network Technology Co., Ltd.
ProductName: Janaei Software Helper
ProductVersion: 1.3.0.0
FileDescription: Janaei Software Helper
Translation: 0x0804 0x03a8

Application.Bundler.228 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 7000000f1 )
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
DrWebAdware.Softcnapp.84
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericIH.S13749768
ALYacGen:Variant.Application.Bundler.228
CylanceUnsafe
ZillyaAdware.KsDler.Win32.150
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaDownloader:Win32/KsDler.2347ba1e
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.2f1420
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.KsDler.A
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
BitDefenderGen:Variant.Application.Bundler.228
NANO-AntivirusRiskware.Win32.Softcnapp.fkcbcj
MicroWorld-eScanGen:Variant.Application.Bundler.228
TencentMalware.Win32.Gencirc.10b7a09a
Ad-AwareGen:Variant.Application.Bundler.228
SophosGeneric PUA PM (PUA)
ComodoApplicUnwnt@#12hp273mr74p8
BitDefenderThetaGen:NN.ZelphiF.34266.NmKfaergRzij
McAfee-GW-EditionBehavesLike.Win32.PUPXFI.jc
FireEyeGeneric.mg.a3ec49e2f14205c7
EmsisoftGen:Variant.Application.Bundler.228 (B)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.Generic.ptl
AviraHEUR/AGEN.1118691
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.319B607
MicrosoftTrojan:Win32/Occamy.C24
GDataGen:Variant.Application.Bundler.228
AhnLab-V3PUP/Win32.Bundler.R241875
Acronissuspicious
McAfeeGenericRXAA-FA!A3EC49E2F142
MAXmalware (ai score=100)
VBA32BScope.Adware.WDJiange
MalwarebytesAdware.Agent
PandaTrj/Genetic.gen
RisingAdware.KsDler!1.B330 (CLASSIC)
YandexTrojan.GenAsa!w+Rv6KS2E9I
IkarusPUA.INNOmod
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Generic
AVGWin32:AdwareX-gen [Adw]

How to remove Application.Bundler.228?

Application.Bundler.228 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment