Malware

What is “Application.Bundler.BBO”?

Malware Removal

The Application.Bundler.BBO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.BBO virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Application.Bundler.BBO?


File Info:

name: A96005BBA3FCF51A06E9.mlw
path: /opt/CAPEv2/storage/binaries/0eb1cf549ae495d6d5ff1007637d07c16907a660c1d363a58df0f687396d94ac
crc32: C6767257
md5: a96005bba3fcf51a06e9d0745e9db526
sha1: 0c8df390fd1e825a7ddc3a21306a8d18f9fa3e7f
sha256: 0eb1cf549ae495d6d5ff1007637d07c16907a660c1d363a58df0f687396d94ac
sha512: 8d98bdeaaa8fac2e77408e1cdbf4ed4d04e908e43d2d74e2ed7910861fd7747338e7c7132c3006f3a3bdd95fb250f8ee973f6d6b44da9a8e2b4654f83e218353
ssdeep: 12288:dUxmxh/s5dmHXFBiZl2u3EgFiWHQOTfAQ6Xyg2XXhiXjgpOR3N7oLmmfwT2+pHT4:dUxkhkHkXFBiZxF4U0Cgzynd8NTqN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1871523421BC1A536D322EEBC5E7C8100642B7A51D878CA7635EE8A6E8F3F1B2D50D371
sha3_384: 9fda8e4db7c252745a0a13acffbeced73ab19918f470872b0074650dcf6aeba5c19bf91dc36aa7e8ad298af1e5cbfbfc
ep_bytes: 558bec83c4c453e9fc99000000000000
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Web Generic
FileDescription: Application Setup
FileVersion:
LegalCopyright: Internet
ProductName: Application
ProductVersion: 1.3
Translation: 0x0000 0x04b0

Application.Bundler.BBO also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Installcore.1!c
DrWebTrojan.InstallCore.1903
CynetMalicious (score: 100)
FireEyeApplication.Bundler.BBO
SkyhighBehavesLike.Win32.Generic.cc
ALYacApplication.Bundler.BBO
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/grayware_confidence_100% (W)
VirITPUP.Win32.Adverts.A
Elasticmalicious (high confidence)
ESET-NOD32Win32/InstallCore.ZAE potentially unwanted
APEXMalicious
ClamAVWin.Malware.Installcore-6954484-0
BitDefenderApplication.Bundler.BBO
NANO-AntivirusVirus.InnoSetup.Gen.ccng
SUPERAntiSpywarePUP.InstallCore/Variant
MicroWorld-eScanApplication.Bundler.BBO
AvastWin32:Evo-gen [Trj]
EmsisoftApplication.Bundler.BBO (B)
F-SecurePotentialRisk.PUA/InstallCore.JR
VIPREApplication.Bundler.BBO
TrendMicroPAK_Xed-21
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
JiangminAdWare.DealPly.lqoo
WebrootAdware.Installcore
AviraPUA/InstallCore.JR
Antiy-AVLVirus/Win32.Expiro.ropf
Kingsoftmalware.kb.a.996
MicrosoftPUADlManager:Win32/InstallCore
XcitiumApplication.Win32.InstallCore.DSG@5ja8xv
ArcabitApplication.Bundler.BBO
ViRobotAdware.Installcore.887256.ASC
GDataWin32.Application.InstallCore.LO
GoogleDetected
AhnLab-V3Adware/Win.Generic.R560671
McAfeeArtemis!A96005BBA3FC
MAXmalware (ai score=70)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallPAK_Xed-21
RisingAdware.InstallCore!1.A30C (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureAdware.not-a-virus.WIN32.AdWare.DealPly.gen_188969
FortinetW32/Wacatac.B!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Application.Bundler.BBO?

Application.Bundler.BBO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment