Malware

Application.Bundler.iStartSurf.FQ removal

Malware Removal

The Application.Bundler.iStartSurf.FQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.iStartSurf.FQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Application.Bundler.iStartSurf.FQ?


File Info:

name: 048C34F428516C35BABC.mlw
path: /opt/CAPEv2/storage/binaries/319233f9705c2c6fce432e414669a035cb2ec71746e06e5549ed1d5dd884654f
crc32: 82D345EB
md5: 048c34f428516c35babcf193a073fee2
sha1: bb6c490b48b1658b95a69fd1f304c5f180ba47c6
sha256: 319233f9705c2c6fce432e414669a035cb2ec71746e06e5549ed1d5dd884654f
sha512: 1dd5cb3785c22822fdabef6c53b4b05f5127585547044d72b9067b516ee7a807440eb3a4812c5a1b128f4436d94e2f68a8aa7a3d535e49364e14c59c68294776
ssdeep: 12288:F4jj7SEojN9ALa+u4ulggq6KFCdTBHTZVck2BPdN:yWV9AG54uigqoDl6k2hd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0A5121879C1C871C5B349311C70E9F696BE7B204E258E6BB7E9CA1D2F760C10E29B67
sha3_384: 8b222d2a69af1d0bbb8852fcbafd39c382110ac6c56d8449833aeba6096108c96d4d27f667f630264126409570acf777
ep_bytes: e803040000e98efeffff558becf64508
timestamp: 2018-05-22 11:21:27

Version Info:

0: [No Data]

Application.Bundler.iStartSurf.FQ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanApplication.Bundler.iStartSurf.FQ
FireEyeGeneric.mg.048c34f428516c35
CAT-QuickHealPUA.PrepscramRI.S19824330
SkyhighBehavesLike.Win32.Autorun.vz
ALYacApplication.Bundler.iStartSurf.FQ
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3122261
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00532d0c1 )
AlibabaTrojan:Win32/Kryptik.6894fcb8
K7GWTrojan ( 005322cc1 )
VirITTrojan.Win32.Vittalia.ZKS
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GGZA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderApplication.Bundler.iStartSurf.FQ
NANO-AntivirusTrojan.Win32.Vittalia.fckrcc
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b285d6
EmsisoftApplication.Bundler.iStartSurf.FQ (B)
F-SecureHeuristic.HEUR/AGEN.1363305
DrWebTrojan.Vittalia.17178
VIPREApplication.Bundler.iStartSurf.FQ
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Bundler.iStartSurf
GDataApplication.Bundler.iStartSurf.FQ
JiangminTrojan.Chapak.it
GoogleDetected
AviraHEUR/AGEN.1363305
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Trojan.Chapak.gen
XcitiumApplication.Win32.IStartSurf.PS@8c4m91
ArcabitApplication.Bundler.iStartSurf.FQ
ViRobotAdware.Istartsurf.2246144.EH
ZoneAlarmHEUR:Trojan.Win32.Chapak.gen
MicrosoftSoftwareBundler:Win32/Prepscram
VaristW32/StartSurf.AE.gen!Eldorado
AhnLab-V3PUP/Win32.StartSurf.R228957
Acronissuspicious
McAfeeGenericRXFO-BL!048C34F42851
MAXmalware (ai score=96)
VBA32Adware.Prepscram
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B286 (CLASSIC)
YandexTrojan.GenAsa!tYya3aNgNxs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/GenKryptik.CGJG!tr
BitDefenderThetaGen:NN.ZexaF.36680.jAW@aq@UPKni
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Application.Bundler.iStartSurf.FQ?

Application.Bundler.iStartSurf.FQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment