Malware

AdWare.Win32.StartSurf.arcy malicious file

Malware Removal

The AdWare.Win32.StartSurf.arcy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.arcy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

live.windowchannel.bid
gool.eventhammer.bid

How to determine AdWare.Win32.StartSurf.arcy?


File Info:

crc32: F897AEA5
md5: 246faf2884eb4df5e3961bade70da17e
name: 246FAF2884EB4DF5E3961BADE70DA17E.mlw
sha1: d3b2d699573db94f08e8e34f308d70bee7e49319
sha256: 021a36cc15e0a0973ecdef4accef8cef70760777098811e6b35c32d222667086
sha512: 6308c78bcd250b8524e3500002193bf47512924d54c26b0fc8d8ce0622c06030ad5901c01d57ac1563e40c8190e825bc5ca7ba5c6a070c582da257885f6a56f4
ssdeep: 24576:umwz9eoQlLeGQzCgdl628LKjw333bK7v:fwRNQlLeGXMdmK83e7v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
FileVersion: 1.0.0.1
OriginalFilename: Template.exe
ProductVersion: 1.0.0.7
Translation: 0x0419 0x04b0

AdWare.Win32.StartSurf.arcy also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00528e801 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.13872
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.30885
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaAdWare:Win32/StartSurf.90350450
K7GWTrojan ( 00528e801 )
Cybereasonmalicious.884eb4
CyrenW32/S-94e15fbb!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FZVG
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.arcy
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusRiskware.Win32.StartSurf.evzwgv
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10b106e9
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/Generic-S
ComodoApplication.Win32.IStartSurf.HR@7fe0b8
BitDefenderThetaGen:NN.ZexaF.34170.5C0@a4wW!nii
VIPREAdware.Win32.StartSurf
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.246faf2884eb4df5
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.ajs
AviraHEUR/AGEN.1103345
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.233C583
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareAdware.ConvertAd/Variant
GDataGen:Heur.Mint.Zamg.1
TACHYONTrojan/W32.Agent.934912.AN
AhnLab-V3Adware/Win32.StartSurf.R215842
Acronissuspicious
McAfeePacked-VV!246FAF2884EB
MAXmalware (ai score=100)
VBA32AdWare.StartSurf
MalwarebytesEmotet.Trojan.Stealer.DDS
PandaTrj/Genetic.gen
RisingPUF.Prepscram!1.AEAF (CLASSIC)
YandexTrojan.GenAsa!wCEtqqEiEqg
IkarusTrojan.Crypt
FortinetW32/Kryptik.FZVG!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.StartSurf.arcy?

AdWare.Win32.StartSurf.arcy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment