Malware

About “Application.Bundler.380” infection

Malware Removal

The Application.Bundler.380 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.380 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Bundler.380?


File Info:

name: 315FD48CB80AD1ADF1D8.mlw
path: /opt/CAPEv2/storage/binaries/806c4fe069f7a3e984065ad59ce141c2b5b0413b4186ddbb6f200c6e17b3c3b3
crc32: 97120CE0
md5: 315fd48cb80ad1adf1d8121c3e15692f
sha1: e6bb049b41cf49665bc883d3649e438c6969bb0b
sha256: 806c4fe069f7a3e984065ad59ce141c2b5b0413b4186ddbb6f200c6e17b3c3b3
sha512: a2895a15dddeede633244f5488a17b506f083462940e7fa70dcdae9321b191a1117639223ed5b294541590ac735abdcac54f257685a1c956072d6fc942378f4d
ssdeep: 12288:d4BFtvhLsqMZxhsMjcUKtzdsEsdSDNRntC1/fn58qvueVWzGXuA:WEZxSzmnGNwH58qvxMzG3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173E423835ACE90CDC94136730493DAA1A799FD6A8B58CB130DF18F36A9B36D68532743
sha3_384: 51a2d88533ada22b2e73fa59ee886dcc9030a666f422e1d7289fc0b48010f19a4d70bab03606389441e5e9d01d88844d
ep_bytes: 60be00704a008dbe00a0f5ffc7871047
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Application.Bundler.380 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.Bundler.380
SkyhighArtemis!PUP
ALYacGen:Variant.Application.Bundler.380
Cylanceunsafe
ZillyaTrojan.InstallCoreCRTD.Win32.4298
SangforTrojan.Win32.Save.a
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
ArcabitTrojan.Application.Bundler.380
VirITAdware.Win32.InstallCore.EC
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/InstallCore.BH potentially unwanted
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.InstallCore.gen
BitDefenderGen:Variant.Application.Bundler.380
NANO-AntivirusTrojan.Win32.InstallCore.cqteka
SUPERAntiSpywarePUP.InstallCore/Variant
TencentMalware.Win32.Gencirc.10b3abc4
EmsisoftApplication.Generic (A)
F-SecurePotentialRisk.PUA/InstallCore.Gen7
DrWebAdware.InstallCore.106
VIPREGen:Variant.Application.Bundler.380
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.315fd48cb80ad1ad
SophosGeneric Reputation PUA (PUA)
JiangminAdWare.Generic.cznr
Webroot.Adware.Installcore.Gen
VaristW32/InstallCore.G.gen!Eldorado
AviraPUA/InstallCore.Gen7
MAXmalware (ai score=74)
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumApplicUnwnt@#7kms4kwm5yxg
MicrosoftPUADlManager:Win32/InstallCore
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataWin32.Application.InstallCore.LH
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.InstallCore.R175631
McAfeeArtemis!315FD48CB80A
GoogleDetected
VBA32Downware.InstallCore
MalwarebytesPUP.Optional.InstallCore.DDS
RisingAdware.InstallCore!8.A18D (TFE:5:9hi9iE1dDiR)
YandexPUA.InstallCore!tJ0DKpiFs1Y
IkarusSoftwareBundler
MaxSecureTrojan.Malware.500359.susgen
FortinetAdware/Fam.NB
DeepInstinctMALICIOUS

How to remove Application.Bundler.380?

Application.Bundler.380 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment