Malware

About “SoftwareBundler:Win32/Dlhelper!pz” infection

Malware Removal

The SoftwareBundler:Win32/Dlhelper!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SoftwareBundler:Win32/Dlhelper!pz virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine SoftwareBundler:Win32/Dlhelper!pz?


File Info:

name: 325FAD6EFF06B8B527DE.mlw
path: /opt/CAPEv2/storage/binaries/dab8373823ce3ae4af626560046235d56f8a9cdc5a29b87cac53cde65638a10e
crc32: 35FA1355
md5: 325fad6eff06b8b527de4ba4060d6c07
sha1: 35a5dbe1ce741760707185839eee046e232ba72e
sha256: dab8373823ce3ae4af626560046235d56f8a9cdc5a29b87cac53cde65638a10e
sha512: 7ec864d6eec77b99c6001775497f5f640cbd4fdf7f7a919fd700ceade43cb37005489a9b15d070b14e83afdf47b5821c9125181cc23720db2edfeaae8e9d86ed
ssdeep: 24576:poSUF/QB+9Oczr6vmOsrGE0DWDZAEhdxQa0AdgNg1Wz3Pk6JayGEh:iv/ukr6emwAOQqI2S3My7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F55ACA189C56C09DC64CE39F6957FE3E2020E76392DD73C2D6D730A16BA96ACCC5E04
sha3_384: d5ec7eeb7abfab41c8240ab0c4db3b50683c9afe3214f6456c2d5560d5a5b52ff3ff62e86003c91fa7e745bc3eefdcdc
ep_bytes: 60be00b064008dbe0060dbffc787346c
timestamp: 2015-01-17 11:07:09

Version Info:

FileVersion: 1.9.0.0
ProductVersion: 1.9.0.0
Translation: 0x0409 0x04e4

SoftwareBundler:Win32/Dlhelper!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Application.Bundler.DlHelper.2
FireEyeGeneric.mg.325fad6eff06b8b5
SkyhighGenericRXFE-WG!0359FC254F24
ALYacGen:Variant.Application.Bundler.DlHelper.2
ZillyaAdware.DlHelperCRTD.Win32.4759
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0040fa1b1 )
K7GWUnwanted-Program ( 0040fa1b1 )
Cybereasonmalicious.eff06b
VirITPUP.Win32.KiaForv.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Dlhelper.AK potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Downloader-66484
Kasperskynot-a-virus:HEUR:AdWare.Win32.DownloadHelper.gen
BitDefenderGen:Variant.Application.Bundler.DlHelper.2
NANO-AntivirusTrojan.Win32.Strictor.dnkbno
AvastWin32:OutBrowse-EP [PUP]
EmsisoftApplication.AdBrowse (A)
F-SecurePotentialRisk.PUA/Dlhelper.Gen7
DrWebTrojan.DownLoader12.21590
VIPREGen:Variant.Application.Bundler.DlHelper.2
Trapminemalicious.high.ml.score
SophosDLHelper (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminPacked.Upantix.ph
GoogleDetected
AviraPUA/Dlhelper.Gen7
VaristW32/Dlhelper.E.gen!Eldorado
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftSoftwareBundler:Win32/Dlhelper!pz
XcitiumApplication.Win32.Dlhelper.DFC@8n47v5
ArcabitTrojan.Application.Bundler.DlHelper.2
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.DownloadHelper.gen
GDataWin32.Application.Dlhelper.D
CynetMalicious (score: 99)
McAfeeGenericRXAA-AA!325FAD6EFF06
MAXmalware (ai score=71)
VBA32BScope.Adware.DownloadHelper
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingAdware.InstallMonster!1.D4ED (CLASSIC)
YandexTrojan.GenAsa!f84L1spyujo
IkarusPUA.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Dlhelper
BitDefenderThetaGen:NN.ZelphiF.36802.qnLfamP7Ktai
AVGWin32:OutBrowse-EP [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove SoftwareBundler:Win32/Dlhelper!pz?

SoftwareBundler:Win32/Dlhelper!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment