Malware

How to remove “AdWare.Win32.StartSurf.brhm”?

Malware Removal

The AdWare.Win32.StartSurf.brhm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.brhm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

all.fingersleep.bid
none.coalrate.men

How to determine AdWare.Win32.StartSurf.brhm?


File Info:

crc32: B81D2F6E
md5: ef2324b3754262b3c2857d227ab1ade3
name: EF2324B3754262B3C2857D227AB1ADE3.mlw
sha1: ab16806ede19ee53760c6e6525c1654e0ec7bc5d
sha256: 20575014c4beb81a6e2ccbedbd998864b76a99cde84abf22217707e18e3e0876
sha512: 019b8940866bc3e5949c0369ec0fba93507dc70f4f2abe527daadbce24369f69adbe0781020f44bf45e93f985c2108b7c7486814830a2c7995cb1eb749864fde
ssdeep: 24576:e5spUpilkxQ9xRWXlALABG1oTgku3pBeGMXTu2u5mMD:e5liSQPoVPfTg1oqwm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Tcedaihu iltiilig
InternalName: OKOSSEATUSR.EXE
FileVersion: 3.0.10.0
CompanyName: xa9Tcedaihu iltiilig
ProductName: OKOSSEATUSR
ProductVersion: 3.0.10.0
OriginalFilename: okosseatusr.exe
Translation: 0x0409 0x04e4

AdWare.Win32.StartSurf.brhm also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053b81d1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17914
CynetMalicious (score: 100)
CAT-QuickHealSwbndlr.Dlhelper.V2
ALYacApplication.Bundler.iStartSurf.1.Gen
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/StartSurf.a901f741
K7GWTrojan ( 0053b81d1 )
Cybereasonmalicious.375426
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJAJ
APEXMalicious
AvastFileRepMalware
Kasperskynot-a-virus:AdWare.Win32.StartSurf.brhm
BitDefenderApplication.Bundler.iStartSurf.1.Gen
NANO-AntivirusRiskware.Win32.StartSurf.ffotpr
MicroWorld-eScanApplication.Bundler.iStartSurf.1.Gen
TencentMalware.Win32.Gencirc.114cf8b2
Ad-AwareApplication.Bundler.iStartSurf.1.Gen
SophosGeneric PUA KL (PUA)
ComodoApplication.Win32.Dlhelper.GE@8159h4
BitDefenderThetaGen:NN.ZexaF.34294.Lr0@aO@VV!ki
McAfee-GW-EditionBehavesLike.Win32.PUPXFI.tm
FireEyeGeneric.mg.ef2324b3754262b3
EmsisoftApplication.Bundler.iStartSurf.1.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen4
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2708BBB
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataApplication.Bundler.iStartSurf.1.Gen
Acronissuspicious
McAfeePacked-FKC!EF2324B37542
MAXmalware (ai score=96)
VBA32BScope.Adware.AdLoad
MalwarebytesAdware.DLAssistant
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexTrojan.GenAsa!r9M4J5OevQI
IkarusPUA.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CFOO!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove AdWare.Win32.StartSurf.brhm?

AdWare.Win32.StartSurf.brhm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment