Malware

AdWare.StartSurf removal

Malware Removal

The AdWare.StartSurf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.StartSurf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine AdWare.StartSurf?


File Info:

crc32: EFDE3E2E
md5: 7b9c085675128503a367350e834f4e63
name: 7B9C085675128503A367350E834F4E63.mlw
sha1: 7c89457c808f66ff1f30f5e578f5ff4d07748b2f
sha256: 57a1418e1aa5897f7ddd350390c5d197311f8c9b1e5c22c093c4c9cbb502b616
sha512: 12ccb6a57b759f78fa547cedd99f0c0463aa8535ba5af9bb9d8d2ea93d60af9ad61d3b8a542e4a9e3cf9bd44c6f428b7572ff0db0b5d281bde420545495691e4
ssdeep: 12288:k9S+aqQvwHBLOwc077x1GAE1MF5VvQBO:Vvh0LOFO7x1gY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: TemplatelExeFile.rc
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: TemplatelExeFile.rc
Translation: 0x0419 0x04b0

AdWare.StartSurf also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00528e801 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.12815
CynetMalicious (score: 100)
CAT-QuickHealSoftwareBundler.Prepscram.A7
ALYacGen:Variant.ClipBanker.215
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.12263
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/StartSurf.f85f4183
K7GWTrojan ( 0050f44b1 )
Cybereasonmalicious.675128
CyrenW32/S-10b1690a!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Kryptik.FTMV
APEXMalicious
AvastFileRepMetagen [Malware]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.abpz
BitDefenderGen:Variant.ClipBanker.215
NANO-AntivirusRiskware.Win32.StartSurf.epsnxd
SUPERAntiSpywarePUP.Bundler/Variant
MicroWorld-eScanGen:Variant.ClipBanker.215
TencentMalware.Win32.Gencirc.10b2db61
Ad-AwareGen:Variant.ClipBanker.215
SophosGeneric PUA HM (PUA)
BitDefenderThetaGen:NN.ZexaF.34628.Ry0@a8fnMlok
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OLF20
McAfee-GW-EditionBehavesLike.Win32.Generic.jm
FireEyeGeneric.mg.7b9c085675128503
EmsisoftGen:Variant.ClipBanker.215 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.afe
AviraHEUR/AGEN.1103317
eGambitUnsafe.AI_Score_99%
MicrosoftSoftwareBundler:Win32/Prepscram
ArcabitTrojan.ClipBanker.215
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.ClipBanker.215
AhnLab-V3PUP/Win32.StartSurf.R204081
Acronissuspicious
McAfeePUP-XBS-KX
MAXmalware (ai score=80)
VBA32AdWare.StartSurf
MalwarebytesGeneric.Trojan.Bundler.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0OLF20
RisingTrojan.Kryptik!1.AB1C (CLOUD)
YandexTrojan.GenAsa!IRcZAhjZ7uU
IkarusPUA.Bundler
FortinetW32/Kryptik.GGTA!tr
AVGFileRepMetagen [Malware]
Qihoo-360Win32/Adware.Generic.HgIASOkA

How to remove AdWare.StartSurf?

AdWare.StartSurf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment