Malware

How to remove “Application.Bundler.iStartSurf.YF”?

Malware Removal

The Application.Bundler.iStartSurf.YF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Bundler.iStartSurf.YF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Bundler.iStartSurf.YF?


File Info:

name: A8613CB8059571D8EC3F.mlw
path: /opt/CAPEv2/storage/binaries/b04a9b1132d7d3ded3308e2ab73b506263f05a7a176a67c377cb2ca1dc87ffc5
crc32: D42AD210
md5: a8613cb8059571d8ec3f4c69eb21f076
sha1: 56246124de1ee5ecee1211545a8d20b6ad786ebd
sha256: b04a9b1132d7d3ded3308e2ab73b506263f05a7a176a67c377cb2ca1dc87ffc5
sha512: 4dca3552eaf952f22ba123a2bf6053a6b37f20f1c45b09d233f6a99ddaa5e17c6f02c1d0b1593bb914e149764d9177ce37efad54c5ab110882c91f71172d8634
ssdeep: 12288:36eG1ujSyijgt3T70qnJuSmXSAST8lUcDQA/pA/JWMLzZgJ:xL2I3T7VufSUNC/J1a
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12EB5F160B5E38036E9B30C3458788A595A2CFA213B354DFF23D756AD4E74AC28931D7B
sha3_384: e7440a3541c01eab42a779bc69a8d4ff84f171e656576b89b93678afbaad7faac677bc873875c70557a13ef6e83e2ab8
ep_bytes: e88e070000e974feffffe9f337000055
timestamp: 2018-11-11 09:48:02

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
LegalCopyright: Copyright (C) 2018
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0419 0x04b0

Application.Bundler.iStartSurf.YF also known as:

BkavW32.AIDetectMalware
AVGWin32:AdwareX-gen [Adw]
DrWebTrojan.Vittalia.13656
MicroWorld-eScanApplication.Bundler.iStartSurf.YF
FireEyeGeneric.mg.a8613cb8059571d8
CAT-QuickHealPUA.PrepscramPMF.S19754610
SkyhighGenericRXGP-CF!A8613CB80595
McAfeeGenericRXGP-CF!A8613CB80595
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054256c1 )
AlibabaTrojan:Win32/Chapak.cc313cc1
K7GWTrojan ( 0054256c1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36802.lw0@a4mArGgk
VirITTrojan.Win32.Vittalia.UFG
SymantecAdware.IstartSurf
ESET-NOD32a variant of Win32/Kryptik.GMVM
CynetMalicious (score: 99)
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Malware.Istartsurf-6872838-0
KasperskyTrojan.Win32.Chapak.bfeo
BitDefenderApplication.Bundler.iStartSurf.YF
NANO-AntivirusTrojan.Win32.Vittalia.fkbsyv
RisingTrojan.Kryptik!8.8 (TFE:5:VTnbUbp616K)
SophosTroj/Agent-BADC
F-SecureHeuristic.HEUR/AGEN.1305943
ZillyaTrojan.Chapak.Win32.35838
TrendMicroTROJ_GEN.R002C0PB524
EmsisoftApplication.Bundler.iStartSurf.YF (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Chapak.acs
VaristW32/S-41de8388!Eldorado
AviraHEUR/AGEN.1305943
MAXmalware (ai score=100)
Antiy-AVLGrayWare[AdWare]/Win32.Kryptik.gmts
KingsoftWin32.Trojan.Chapak.bfeo
MicrosoftSoftwareBundler:Win32/Prepscram
XcitiumApplication.Win32.IStartSurf.PS@8c4m91
ArcabitApplication.Bundler.iStartSurf.YF
ViRobotAdware.Prepscram.2293248.YL
ZoneAlarmTrojan.Win32.Chapak.bfeo
GDataApplication.Bundler.iStartSurf.YF
GoogleDetected
AhnLab-V3PUP/Win32.IStartSurf.R243822
VBA32BScope.Adware.Prepscram
ALYacApplication.Bundler.iStartSurf.YF
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PB524
TencentMalware.Win32.Gencirc.10b2c017
YandexTrojan.GenAsa!3PLNYB0rCEU
IkarusPUA.Win32.Prepscram
MaxSecureTrojan.Malware.73900664.susgen
FortinetW32/GenKryptik.CUPB!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Kryptik.GLRK

How to remove Application.Bundler.iStartSurf.YF?

Application.Bundler.iStartSurf.YF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment