Malware

Should I remove “Application.Bundler.iStartSurf.AHQ”?

Malware Removal

The Application.Bundler.iStartSurf.AHQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.iStartSurf.AHQ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to identify installed AV products by registry key
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

ec2-52-87-100-16.compute-1.amazonaws.com
alt.tubgiants.host
com.bushesstocking.icu

How to determine Application.Bundler.iStartSurf.AHQ?


File Info:

crc32: 7900388F
md5: f56380abb669d76ee329160e90601739
name: slush_hack.exe
sha1: 15bdf5f9e046afaa06032770f83a728e8ea06a4d
sha256: 618bc97b55b88a13b6783df20665e4e8ee9050fa76c903aa1d48afbac45c405a
sha512: 6ee7fce9c0da3b952224ce03eb011c2630756e57f9a17be0b29a0c32cbad8f3d2bc3e6a3363292a2b64fb06c4c6813e62e3a28594958224baeae373f53139032
ssdeep: 24576:Y5gTv38OnHF60CqP6gW/5FiVOP/NWozlVrnPDO/CaK+ME9jQ+ELRW9PSvsWiLP:EOHHCrJa8DOuRM0sWiL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Application.Bundler.iStartSurf.AHQ also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanApplication.Bundler.iStartSurf.AHQ
FireEyeGeneric.mg.f56380abb669d76e
CAT-QuickHealTrojan.Wacatac
Qihoo-360Win32/Virus.Adware.059
McAfeePacked-FPY!F56380ABB669
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00549c091 )
BitDefenderApplication.Bundler.iStartSurf.AHQ
K7GWTrojan ( 00549c091 )
Cybereasonmalicious.bb669d
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34130.@tW@aaAxrip
F-ProtW32/S-7e6557ff!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GNDF
APEXMalicious
AvastWin32:Dropper-gen [Drp]
GDataApplication.Bundler.iStartSurf.AHQ
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
AlibabaTrojan:Win32/Kryptik.6c8d9db5
NANO-AntivirusTrojan.Win32.Vittalia.fmdodo
AegisLabAdware.Win32.StartSurf.2!c
TencentWin32.Adware.Generic.Ecjr
Endgamemalicious (high confidence)
EmsisoftApplication.Bundler.iStartSurf.AHQ (B)
ComodoApplicUnwnt@#3jgptsopz794d
F-SecureHeuristic.HEUR/AGEN.1113057
DrWebTrojan.Vittalia.13656
ZillyaAdware.StartSurf.Win32.92673
TrendMicroTrojanSpy.Win32.URSNIF.SMY.hp
Trapminemalicious.high.ml.score
SophosMal/EncPk-ABL
IkarusTrojan.Archive.Agent
CyrenW32/S-7e6557ff!Eldorado
JiangminAdWare.Generic.thfm
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1113057
MAXmalware (ai score=79)
Antiy-AVLGrayWare[AdWare]/Win32.StartSurf
MicrosoftPUA:Win32/Vigua.A
ArcabitApplication.Bundler.iStartSurf.AHQ
AhnLab-V3PUP/Win32.IStartSurf.C2951952
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
CynetMalicious (score: 100)
Acronissuspicious
VBA32Adware.StartSurf
Ad-AwareApplication.Bundler.iStartSurf.AHQ
MalwarebytesAdware.IStartSurf
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMY.hp
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexPUA.StartSurf!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GNDZ!tr
AVGWin32:Dropper-gen [Drp]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Application.Bundler.iStartSurf.AHQ?

Application.Bundler.iStartSurf.AHQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment