Malware

Application.Bundler.RelevantKnowledge.3 (B) (file analysis)

Malware Removal

The Application.Bundler.RelevantKnowledge.3 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.RelevantKnowledge.3 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Application.Bundler.RelevantKnowledge.3 (B)?


File Info:

name: B96F02F8865B0E8AF1CE.mlw
path: /opt/CAPEv2/storage/binaries/7ef44c12ab9cef3e8d6c63b9db78140b21574d40acd519e97c07b828802bab97
crc32: 761B7A15
md5: b96f02f8865b0e8af1cef539fa3e9978
sha1: 58b1c548d8667cfe0055dd8f34ee83c1c2c413ec
sha256: 7ef44c12ab9cef3e8d6c63b9db78140b21574d40acd519e97c07b828802bab97
sha512: 0574162f35290ac2f3537b30092786385387275491348443b6a2e8fb8e8c138b29fa1d73b398b6839f9d2f7b49818fe7fbd61909b8647aeaf0a37f749f26cf4b
ssdeep: 196608:D8hD8Mtymq7cJ7Awra0PD4rlaGBTR6iK6i0PDoMw7CH46rWNJUt8Ky:D8h8sBqe3vEr4GBTsv0PDQCHTrS2t8Ky
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173B6233FB268653FD4AB5B32457393108A7BBA61601B8D2E57F4441DCF660B01E3FA26
sha3_384: ea8da8179f6b6ddd2dec90f6569b010499b7d4d86e40ca24cd58559421626fca52b82615136f5a920ce0da201e8e0912
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-05-21 05:56:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: FalcoWare, Inc.
FileDescription: Falco Christmas Gems Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Falco Christmas Gems
ProductVersion:
Translation: 0x0000 0x04b0

Application.Bundler.RelevantKnowledge.3 (B) also known as:

Elasticmalicious (high confidence)
DrWebAdware.Downware.19763
MicroWorld-eScanGen:Variant.Application.Bundler.RelevantKnowledge.3
FireEyeGen:Variant.Application.Bundler.RelevantKnowledge.3
ALYacGen:Variant.Application.Bundler.RelevantKnowledge.3
CylanceUnsafe
SangforPUP.Win32.Falco.gen
K7AntiVirusAdware ( 005617711 )
K7GWAdware ( 005617711 )
CyrenW32/FalcoBundler.B2.gen!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of MSIL/Falcoware.A potentially unwanted
AvastWin32:VSok-A [PUP]
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:Downloader.Win32.Falco.gen
BitDefenderGen:Variant.Application.Bundler.RelevantKnowledge.3
NANO-AntivirusRiskware.Win32.Falcoware.hiyxxf
Ad-AwareGen:Variant.Application.Bundler.RelevantKnowledge.3
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Variant.Application.Bundler.RelevantKnowledge.3 (B)
Paloaltogeneric.ml
GDataWin32.Application.Falco.A
MicrosoftProgram:Win32/Wacapew.C!ml
McAfeeArtemis!B96F02F8865B
MAXmalware (ai score=72)
VBA32Adware.Downware
MalwarebytesAdware.RelevantKnowledge
APEXMalicious
RisingTrojan.Generic/MSIL@AI.92 (RDM.MSIL:QOyWlLRoHI1JU6julZaB7w)
YandexRiskware.Agent!TLhlcJVrzJw
SentinelOneStatic AI – Malicious PE
AVGWin32:VSok-A [PUP]

How to remove Application.Bundler.RelevantKnowledge.3 (B)?

Application.Bundler.RelevantKnowledge.3 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment