Malware

AdWare.Win32.StartSurf.bsan (file analysis)

Malware Removal

The AdWare.Win32.StartSurf.bsan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.bsan virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

all.fingersleep.bid
none.coalrate.men

How to determine AdWare.Win32.StartSurf.bsan?


File Info:

crc32: D68118AD
md5: dc01cf6a44d243fe0e352a2f21c2f38d
name: DC01CF6A44D243FE0E352A2F21C2F38D.mlw
sha1: 8c6ddf9444e28e74dedcca9e25b5d74c8e1ded30
sha256: 1dde22e88763e844a3c9fafbfad129f3270fed5331a8cc72c11382efbbb5d47d
sha512: e363ea9275c7f354762fc2c933d6a60a42992af6cd10e54d324e506784dbc00c0353de2568788052bdf4fad277d9d0e4a0dcbfd587e0841a176746ceab809c30
ssdeep: 24576:2h4cp2H5ALUz4swaKX5NxBUIXBQHrX/xB0hqaxUGH:22cp2H6hBlAjI/H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Eibgoesri odomahgiehy
InternalName: DOINATCA.EXE
FileVersion: 4.4.9.2
CompanyName: xa9Eibgoesri odomahgiehy
ProductName: DOINATCA
ProductVersion: 4.4.9.2
OriginalFilename: doinatca.exe
Translation: 0x0409 0x04e4

AdWare.Win32.StartSurf.bsan also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17914
CynetMalicious (score: 100)
CAT-QuickHealSwbndlr.Dlhelper.V2
ALYacApplication.Bundler.iStartSurf.1.Gen
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.55748
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/StartSurf.6e58ad8f
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.a44d24
CyrenW32/S-410bae86!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIPK
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.bsan
BitDefenderApplication.Bundler.iStartSurf.1.Gen
NANO-AntivirusRiskware.Win32.StartSurf.ffrfak
MicroWorld-eScanApplication.Bundler.iStartSurf.1.Gen
TencentMalware.Win32.Gencirc.10c9182b
Ad-AwareApplication.Bundler.iStartSurf.1.Gen
SophosGeneric PUA IM (PUA)
ComodoApplication.Win32.Dlhelper.GE@8159h4
BitDefenderThetaGen:NN.ZexaF.34266.Or0@a0LI99ni
McAfee-GW-EditionBehavesLike.Win32.ExtenBro.tt
FireEyeGeneric.mg.dc01cf6a44d243fe
EmsisoftApplication.Bundler.iStartSurf.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.ccd
AviraHEUR/AGEN.1101341
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2711E9D
MicrosoftTrojan:Win32/Occamy.C
ArcabitApplication.Bundler.iStartSurf.1.Gen
GDataApplication.Bundler.iStartSurf.1.Gen
AhnLab-V3PUP/Win32.StartSurf.R232935
Acronissuspicious
McAfeePacked-FKC!DC01CF6A44D2
MAXmalware (ai score=91)
VBA32Trojan.Vittalia
MalwarebytesAdware.DLAssistant.Generic
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B33C (CLASSIC)
IkarusPUA.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CFOO!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.StartSurf.bsan?

AdWare.Win32.StartSurf.bsan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment