Malware

MemScan:Application.Bundler.Outbrowse.E removal guide

Malware Removal

The MemScan:Application.Bundler.Outbrowse.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Application.Bundler.Outbrowse.E virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

installer.ppdownload.com
www.hugedomains.com

How to determine MemScan:Application.Bundler.Outbrowse.E?


File Info:

crc32: 3856555D
md5: 2b9ad719b2f625b9c015f0802fe1bdcc
name: 2B9AD719B2F625B9C015F0802FE1BDCC.mlw
sha1: 9ee9e777c5d64b03593a25b874b99b1ceac5b135
sha256: 159e029356a0f43547f2379f245f1b16ec5747450194daafc32ce145ac26d6d4
sha512: 1ab74bdcd421b9b9c42c0e2690d9ddb004791eb7bfde042a8ac53072c5ba5feca44697afedf09ff20ed1d9f6bab0fa70a943c2c5f161d3798d970417790cdba3
ssdeep: 24576:kL7uqKtkypjdiIxadbQCt13is4kLny5cuqtXFSVTQUN:kL7VBGeb7vSslny5BaUN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: lc
FileVersion: 3.4.5.6
CompanyName: cn
ProductName: pn
CompiledBy: Compiled by SFXMaker
ProductVersion: 3.4.5.6
FileDescription: fd
Translation: 0x0400 0x04b0

MemScan:Application.Bundler.Outbrowse.E also known as:

LionicRiskware.Win32.Agent.1!c
DrWebAdware.Downware.3973
CynetMalicious (score: 100)
ALYacMemScan:Application.Bundler.Outbrowse.E
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.9b2f62
CyrenTrojan!9d14
SymantecTrojan.Gen.2
ESET-NOD32Win32/OutBrowse.S potentially unwanted
APEXMalicious
AvastNSIS:OutBrowse-C [PUP]
Kasperskynot-a-virus:Downloader.Win32.Agent.bvbo
BitDefenderMemScan:Application.Bundler.Outbrowse.E
NANO-AntivirusTrojan.Win32.OutBrowse.dgnlgr
MicroWorld-eScanMemScan:Application.Bundler.Outbrowse.E
TencentWin32.Trojan.Outbrowse.Htmo
SophosGeneric PUA JO (PUA)
VIPREOutBrowse (fs)
TrendMicroTROJ_SPNR.08JQ15
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.tc
FireEyeMemScan:Application.Bundler.Outbrowse.E
EmsisoftMemScan:Application.Bundler.Outbrowse.E (B)
JiangminAdWare.OutBrowse.jao
AviraPUA/Outbrowse.Gen
Antiy-AVLTrojan/Generic.ASBOL.2B2B
KingsoftWin32.Troj.DownAgent.bv.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataMemScan:Application.Bundler.Outbrowse.E
McAfeeArtemis!2B9AD719B2F6
MAXmalware (ai score=78)
VBA32Adware.OutBrowse
MalwarebytesTrojan.Zbot
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_SPNR.08JQ15
RisingTrojan.Generic@ML.100 (RDML:y++rGRa+QwyY4q8rk9DYkg)
YandexPUA.Downloader!ih9tCM0WPWM
IkarusPUA.OutBrowse
FortinetRiskware/Generic
AVGNSIS:OutBrowse-C [PUP]
Paloaltogeneric.ml

How to remove MemScan:Application.Bundler.Outbrowse.E?

MemScan:Application.Bundler.Outbrowse.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment