Malware

What is “Application.Bundler.iStartSurf.XM”?

Malware Removal

The Application.Bundler.iStartSurf.XM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.iStartSurf.XM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Application.Bundler.iStartSurf.XM?


File Info:

name: B042EDBDFD44C020AB19.mlw
path: /opt/CAPEv2/storage/binaries/7a3859bb2df87f6ddd1ec7a9e5ca739a204cd794d83d06fb50dd7b2937c8cbc6
crc32: D4290AB3
md5: b042edbdfd44c020ab19ae3197d7fdb6
sha1: 8ca9c103e7b0239662b42a31ad7af50ecf3f99b6
sha256: 7a3859bb2df87f6ddd1ec7a9e5ca739a204cd794d83d06fb50dd7b2937c8cbc6
sha512: 1855d165435bef27006f6c61bc9fe52d6c9f455637ebab7ceef9540d1d6732d1465b856f0fdfadf31b47867251cc24815fda54bd40e48a74553d0e5b6b2f259d
ssdeep: 24576:qhbvoyGx4gXM7DO2zQDIfBA07YV5+R3A/cVaMO/j:qNzgXMnzQkfBA07y8Y7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EC95D020B5B2E037D8B340B48978966A517DFB310F2548EF63C8292E6F755D2AB31637
sha3_384: d3faf31bbb742160217735f3172a7f4a07d516366bab96b92e84f8597d06ce280de6dd90049a567b08fc4baac1f5a661
ep_bytes: e8cd080000e974feffffe9265f000055
timestamp: 2018-11-06 11:58:13

Version Info:

0: [No Data]

Application.Bundler.iStartSurf.XM also known as:

LionicTrojan.Win32.Chapak.4!c
tehtrisGeneric.Malware
DrWebTrojan.Vittalia.17867
MicroWorld-eScanApplication.Bundler.iStartSurf.XM
FireEyeGeneric.mg.b042edbdfd44c020
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighGenericRXGP-AR!B042EDBDFD44
McAfeeGenericRXGP-AR!B042EDBDFD44
Cylanceunsafe
ZillyaTrojan.Chapak.Win32.83481
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0054256c1 )
AlibabaTrojan:Win32/Chapak.8c91653c
K7GWTrojan ( 0054256c1 )
ArcabitApplication.Bundler.iStartSurf.XM
BitDefenderThetaGen:NN.ZexaF.36680.ZvW@aulAYhpk
SymantecAdware.IstartSurf
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GMLU
CynetMalicious (score: 99)
APEXMalicious
KasperskyTrojan.Win32.Chapak.bcnm
BitDefenderApplication.Bundler.iStartSurf.XM
NANO-AntivirusTrojan.Win32.Vittalia.fjxhkd
SUPERAntiSpywareAdware.IStartSurf/Variant
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b29775
EmsisoftApplication.Bundler.iStartSurf.XM (B)
F-SecureHeuristic.HEUR/AGEN.1366949
VIPREApplication.Bundler.iStartSurf.XM
SophosTroj/Agent-BADC
IkarusPUA.Win32.Prepscram
JiangminAdWare.StartSurf.rlr
WebrootW32.Adware.Gen
VaristW32/StartSurf.BH.gen!Eldorado
AviraHEUR/AGEN.1366949
Antiy-AVLTrojan/Win32.Chapak
KingsoftWin32.Trojan.Generic.a
XcitiumApplication.Win32.IStartSurf.PS@8c4m91
MicrosoftSoftwareBundler:Win32/Prepscram
ZoneAlarmTrojan.Win32.Chapak.bcnm
GDataApplication.Bundler.iStartSurf.XM
GoogleDetected
AhnLab-V3PUP/Win32.IStartSurf.R243047
VBA32BScope.Adware.Prepscram
ALYacApplication.Bundler.iStartSurf.XM
MAXmalware (ai score=100)
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B4D1 (CLASSIC)
YandexTrojan.GenAsa!aBoZG8M3znw
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.COAQ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (W)

How to remove Application.Bundler.iStartSurf.XM?

Application.Bundler.iStartSurf.XM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment