Malware

Application.Bundler.ATX (file analysis)

Malware Removal

The Application.Bundler.ATX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.ATX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Bundler.ATX?


File Info:

name: 7259EBEFB9CF79FCBF99.mlw
path: /opt/CAPEv2/storage/binaries/b5cea8703874c75170f712e12115b920b7877f75d4ca9373d3b8cf0bc29edbf7
crc32: 2E3AF8F5
md5: 7259ebefb9cf79fcbf99052f18edf914
sha1: 70f98f0059daeec47393d567488c28717bb92474
sha256: b5cea8703874c75170f712e12115b920b7877f75d4ca9373d3b8cf0bc29edbf7
sha512: afa3066cb104d447e72ba47a862003fae797f4b4177abb003b034bd44f429704571f6e6b5c4df546a6de649d8ebc412c66d4de1417a45d36481dd5de38f285cf
ssdeep: 12288:cfksEairhVUeC5l5uKsY4mD5Ww/ni5D6J19x/vW14m56H5TYy7:fsjidOL52KsxG5WwO6J19x/vWEFYI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D685E2DCECB17CDDC29E273DC6817468A094ED3B0D58261AD948330846FB8BE95BB539
sha3_384: b967ab8eb55c358737e17b16c9545ab1f08209215d629240a4f068d94e5185f9230e6414bd082c72675367f6f47e0f67
ep_bytes: e8e6060000e987feffff558beca17030
timestamp: 2018-01-15 12:11:09

Version Info:

0: [No Data]

Application.Bundler.ATX also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.StartSurf.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Bundler.ATX
FireEyeGeneric.mg.7259ebefb9cf79fc
CAT-QuickHealSoftwareBundler.Prepscram.C7
SkyhighBehavesLike.Win32.Generic.tt
McAfeeGenericRXDT-CK!7259EBEFB9CF
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00528e801 )
AlibabaAdWare:Win32/StartSurf.e35e9bda
K7GWTrojan ( 0051ef361 )
CrowdStrikewin/grayware_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36802.XDW@aWrzH4pi
VirITTrojan.Win32.Vittalia.UFG
SymantecAdware.GAIN
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GBQG
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0OB724
Kasperskynot-a-virus:AdWare.Win32.StartSurf.avfi
BitDefenderApplication.Bundler.ATX
NANO-AntivirusRiskware.Win32.StartSurf.exauai
AvastWin32:AdwareX-gen [Adw]
SophosGeneric Reputation PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1317715
DrWebTrojan.Vittalia.13656
VIPREApplication.Bundler.ATX
TrendMicroTROJ_GEN.R002C0OB724
Trapminemalicious.high.ml.score
EmsisoftApplication.Bundler.ATX (B)
IkarusTrojan.Kryptik
GDataApplication.Bundler.ATX
JiangminAdWare.StartSurf.alt
WebrootW32.Adware.Gen
GoogleDetected
AviraHEUR/AGEN.1317715
VaristW32/StartSurf.AT.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.StartSurf
Kingsoftmalware.kb.a.1000
XcitiumApplication.Win32.IStartSurf.BS@7lng48
ArcabitApplication.Bundler.ATX
ViRobotAdware.Startsurf.1861632.EW
ZoneAlarmnot-a-virus:AdWare.Win32.StartSurf.avfi
MicrosoftSoftwareBundler:Win32/Prepscram
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.StartSurf.R217902
Acronissuspicious
VBA32BScope.AdWare.StartSurf
ALYacApplication.Bundler.ATX
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B07C (CLASSIC)
YandexPUA.StartSurf!aIMjCxAo5aY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FWQG!tr
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.fb9cf7
DeepInstinctMALICIOUS

How to remove Application.Bundler.ATX?

Application.Bundler.ATX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment