Malware

How to remove “Application.Bundler.iStartSurf.KX”?

Malware Removal

The Application.Bundler.iStartSurf.KX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.iStartSurf.KX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Bundler.iStartSurf.KX?


File Info:

name: 00F6151D420BE2A53D40.mlw
path: /opt/CAPEv2/storage/binaries/4a37a3cbe3d8bd658dffcf925b2d708fe91a63ef5afb2e760a6557219c86c444
crc32: 81575D13
md5: 00f6151d420be2a53d40efbc94f6d0f8
sha1: 683a39e8a8c13f58fef8e0fb40f5111b1517ede1
sha256: 4a37a3cbe3d8bd658dffcf925b2d708fe91a63ef5afb2e760a6557219c86c444
sha512: c2426e2ad06607806e40b45585e8f7a6af1675adbcac109d477a2d807c455c494015c42fa1954a0a7b7a69ec13b3c350b9d87ad6bbe168db764668423d4117ca
ssdeep: 12288:dzmfT7rrxctrmVX57qx8is5gdmZoEzh+HfnxC8A8PQnIl07Kl8Bif2tB:dzmfX+Z6X08is1fVA5CX8PQIG7gNuB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C595122175EEC473C5B305342828C73A697EBD104A29C7BF37E8261D4EB83D1A575A72
sha3_384: 29a46bb1045f5884c8212bb61336479cb6a85156aca56cba9f5d69bc779924fad37493ab7d11ecbb85ade254063e1006
ep_bytes: e8fd050000e987feffff5064ff350000
timestamp: 2018-10-01 09:41:12

Version Info:

0: [No Data]

Application.Bundler.iStartSurf.KX also known as:

LionicTrojan.Win32.Bundler.4!c
AVGWin32:AdwareX-gen [Adw]
tehtrisGeneric.Malware
DrWebTrojan.Vittalia.17833
MicroWorld-eScanApplication.Bundler.iStartSurf.KX
FireEyeGeneric.mg.00f6151d420be2a5
SkyhighBehavesLike.Win32.Generic.tz
McAfeeGenericRXGM-MW!00F6151D420B
Cylanceunsafe
VIPREApplication.Bundler.iStartSurf.KX
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053e6d21 )
AlibabaTrojan:Win32/Kryptik.dc5b9846
K7GWTrojan ( 0053e6d21 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitApplication.Bundler.iStartSurf.KX
BitDefenderThetaGen:NN.ZexaF.36802.3DW@aqzGMVni
SymantecAdware.IstartSurf
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GKHS
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderApplication.Bundler.iStartSurf.KX
NANO-AntivirusTrojan.Win32.Vittalia.fimokd
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:AdwareX-gen [Adw]
RisingTrojan.Kryptik!1.B54F (CLASSIC)
EmsisoftApplication.Bundler (A)
F-SecureHeuristic.HEUR/AGEN.1360692
ZillyaTrojan.Generic.Win32.675561
TrendMicroTROJ_GEN.R002C0PB624
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Win32.Prepscram
JiangminAdWare.StartSurf.jtl
WebrootW32.Adware.Gen
GoogleDetected
AviraHEUR/AGEN.1360692
MAXmalware (ai score=99)
Antiy-AVLGrayWare[AdWare]/Win32.StartSurf
KingsoftWin32.Trojan.Generic.a
XcitiumApplication.Win32.IStartSurf.PS@8c4m91
MicrosoftSoftwareBundler:Win32/Prepscram
ViRobotAdware.Prepscram.1963520.FC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataApplication.Bundler.iStartSurf.KX
VaristW32/S-6f81026c!Eldorado
AhnLab-V3PUP/Win32.IStartSurf.R238484
Acronissuspicious
ALYacApplication.Bundler.iStartSurf.KX
VBA32BScope.Adware.Prepscram
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PB624
TencentMalware.Win32.Gencirc.10b0b2a0
YandexTrojan.GenAsa!P5OG30RLZcc
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.CGJG!tr
Cybereasonmalicious.d420be
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/IStartSurf.KX

How to remove Application.Bundler.iStartSurf.KX?

Application.Bundler.iStartSurf.KX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment