Malware

How to remove “AdWare.Win32.StartSurf”?

Malware Removal

The AdWare.Win32.StartSurf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine AdWare.Win32.StartSurf?


File Info:

crc32: 106D85D2
md5: 6ccb2b5923524f5df0bc7902c67a0b0b
name: 6CCB2B5923524F5DF0BC7902C67A0B0B.mlw
sha1: 6f25b316368fcc66d9b830c0800a00c8000fedbc
sha256: d0613a8694b78d6cf9f440ecc8ed8aac71bdc85d6696342b4e4347482fd196b7
sha512: a45811886a52c13756ba68548ef386208ed462dd5085881e86627139955d89b7313f4ba646b359bfc5200094cf8def6a705485650342d2bac999c6086634bb32
ssdeep: 12288:GC7eT3oyVyUFzEW/zhwPbLO6yQXznA+wDgIJ3F45Ba:a3lVX67yQjnhwDgQ3F45B
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: TemplatelExeFile.rc
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: TemplatelExeFile.rc
Translation: 0x0419 0x04b0

AdWare.Win32.StartSurf also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00528e801 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.12815
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.Prepscram.EMU.Y7
ALYacGen:Variant.ClipBanker.215
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.12061
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Kryptik.37d2ba69
K7GWTrojan ( 0050eca01 )
Cybereasonmalicious.923524
CyrenW32/S-4ce797cb!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/Kryptik.FSSN
APEXMalicious
AvastFileRepMetagen [Malware]
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
BitDefenderGen:Variant.ClipBanker.215
NANO-AntivirusRiskware.Win32.StartSurf.ephkxd
SUPERAntiSpywarePUP.Bundler/Variant
MicroWorld-eScanGen:Variant.ClipBanker.215
TencentMalware.Win32.Gencirc.10b3a151
Ad-AwareGen:Variant.ClipBanker.215
SophosGeneric PUA GP (PUA)
ComodoApplication.Win32.IStartSurf.BS@7lng48
BitDefenderThetaGen:NN.ZexaF.34628.Gy0@amzDGVak
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OAH21
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.6ccb2b5923524f5d
EmsisoftGen:Variant.ClipBanker.215 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.fzpr
AviraHEUR/AGEN.1103317
eGambitUnsafe.AI_Score_99%
MicrosoftSoftwareBundler:Win32/Prepscram
ArcabitTrojan.ClipBanker.215
AegisLabAdware.Win32.Generic.2!c
GDataGen:Variant.ClipBanker.215
AhnLab-V3PUP/Win32.StartSurf.R201639
Acronissuspicious
McAfeePUP-XBQ-UU
MAXmalware (ai score=89)
VBA32BScope.AdWare.StartSurf
MalwarebytesGeneric.Trojan.Bundler.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0OAH21
RisingTrojan.Kryptik!1.AB1C (CLOUD)
IkarusAdWare.ICLoader
MaxSecureTrojan.Malware.3771246.susgen
FortinetW32/Kryptik.FTMV!tr
AVGFileRepMetagen [Malware]
Qihoo-360Win32/Adware.Generic.HwoCEpsA

How to remove AdWare.Win32.StartSurf?

AdWare.Win32.StartSurf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment