Malware

How to remove “AdWare.Win32.StartSurf.busn”?

Malware Removal

The AdWare.Win32.StartSurf.busn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.busn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

all.fingersleep.bid
none.coalrate.men

How to determine AdWare.Win32.StartSurf.busn?


File Info:

crc32: D86537EE
md5: 3c44ee53a0fd2dd3472a58aca6e8fada
name: 3C44EE53A0FD2DD3472A58ACA6E8FADA.mlw
sha1: 1a170285d020637ae70c20b8c965fd21930da93f
sha256: 1a44b68a9574e6b8f3b1d9960ce299be190b9df0f6abf6f10600631896217e28
sha512: 8b95bba7028152761f517324914a52556de09a87d931fdf0b271c01010efd580ebcc29201986619f3d3f18c245308ba4b6ad5e372d138783fa60d93fe61bd66e
ssdeep: 24576:3IOiYwsONXrXHWdc6WCvVJH5myoDT7YgMWZhFkXMz:3ILBXrXQp9B5m8g7Rkcz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

AdWare.Win32.StartSurf.busn also known as:

K7AntiVirusTrojan ( 0053ba2f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17914
CAT-QuickHealSwbndlr.Dlhelper.V2
ALYacApplication.Bundler.iStartSurf.1.Gen
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3428354
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/StartSurf.5f6c763b
K7GWTrojan ( 0053ba2f1 )
Cybereasonmalicious.3a0fd2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIYH
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.StartSurf.busn
BitDefenderApplication.Bundler.iStartSurf.1.Gen
NANO-AntivirusRiskware.Win32.StartSurf.fhqydv
MicroWorld-eScanApplication.Bundler.iStartSurf.1.Gen
TencentMalware.Win32.Gencirc.114d4d94
Ad-AwareApplication.Bundler.iStartSurf.1.Gen
SophosMal/EncPk-AOA
ComodoApplication.Win32.Dlhelper.GI@8159ae
BitDefenderThetaGen:NN.ZexaF.34236.nsW@aecZALji
TrendMicroTROJ_GEN.R002C0PIJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.vz
FireEyeGeneric.mg.3c44ee53a0fd2dd3
EmsisoftApplication.Bundler.iStartSurf.1.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen4
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2726AEE
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitApplication.Bundler.iStartSurf.1.Gen
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataApplication.Bundler.iStartSurf.1.Gen
AhnLab-V3PUP/Win32.StartSurf.C2655140
Acronissuspicious
McAfeePacked-FKC!3C44EE53A0FD
MAXmalware (ai score=73)
VBA32Trojan.Vittalia
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PIJ21
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexTrojan.GenAsa!QD0f6HEJU58
IkarusPUA.Win32.Prepscram
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CFOO!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove AdWare.Win32.StartSurf.busn?

AdWare.Win32.StartSurf.busn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment