Adware

Adware.StartSurf malicious file

Malware Removal

The Adware.StartSurf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.StartSurf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

Related domains:

lamp.troublerifle.bid
light.representativeglass.bid

How to determine Adware.StartSurf?


File Info:

crc32: 21774B63
md5: dbc1324b04b5c17d6873ecc1ffe05145
name: DBC1324B04B5C17D6873ECC1FFE05145.mlw
sha1: cff25efdfd6c21895e493335b1163969f052401b
sha256: 4f8d864801e78d10db09937b904b1453c2cfa320a57e6b00431d2b7432237cfb
sha512: a532390be5cf2e384f207559b9a9ca5851c2844f7842119951559d02838e51f3664f704e65c909da7ae3873c06a6d865add8a87f97752acf242e6508779ba6a5
ssdeep: 12288:riwWKJH/LYN+7nLWG82tg6Jvl52hU9B99aN1mOT2VZnlF:riwWKR/sN+WGg6Jvl52+99B1VZn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
Translation: 0x0419 0x04b0

Adware.StartSurf also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.14640
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1787
FireEyeGeneric.mg.dbc1324b04b5c17d
CAT-QuickHealSWB.Prepscram.JK6
ALYacGen:Variant.Ransom.GandCrab.1787
MalwarebytesAdware.IStartSurf
VIPRETrojan.Win32.Generic!BT
AegisLabAdware.Win32.Generic.2!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00528e801 )
BitDefenderGen:Variant.Ransom.GandCrab.1787
K7GWTrojan ( 005267551 )
Cybereasonmalicious.b04b5c
BitDefenderThetaGen:NN.ZexaF.34590.pz0@aSKZhHbk
CyrenW32/S-ec8ab2eb!Eldorado
SymantecAdware.IstartSurf
ESET-NOD32a variant of Win32/Kryptik.GCWT
APEXMalicious
AvastFileRepMetagen [Malware]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaTrojan:Win32/Kryptik.9a9f09d5
NANO-AntivirusRiskware.Win32.Vittalia.eydedk
RisingTrojan.Kryptik!1.B032 (CLOUD)
Ad-AwareGen:Variant.Ransom.GandCrab.1787
EmsisoftGen:Variant.Ransom.GandCrab.1787 (B)
ComodoApplication.Win32.IStartSurf.BS@7lng48
F-SecureHeuristic.HEUR/AGEN.1103309
ZillyaAdware.Generic.Win32.77284
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
SophosGeneric PUA MP (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.mdax
AviraHEUR/AGEN.1103309
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftSoftwareBundler:Win32/Prepscram
ArcabitTrojan.Ransom.GandCrab.D6FB
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataGen:Variant.Ransom.GandCrab.1787
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.IStartSurf.R220101
Acronissuspicious
McAfeePacked-ZA!DBC1324B04B5
VBA32Adware.StartSurf
CylanceUnsafe
PandaTrj/Genetic.gen
TencentWin32.Adware.Generic.Wvan
YandexTrojan.GenAsa!FWPhcEJUJ/g
IkarusTrojan.Kryptik
eGambitUnsafe.AI_Score_100%
FortinetW32/Kryptik.FXGV!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/Trojan.177

How to remove Adware.StartSurf?

Adware.StartSurf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment