Malware

AdWare.Win32.StartSurf.cfgi removal tips

Malware Removal

The AdWare.Win32.StartSurf.cfgi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.cfgi virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

Related domains:

wpad.local-net
dill.orangessmoke.xyz
potato.giraffegiraffe.website

How to determine AdWare.Win32.StartSurf.cfgi?


File Info:

name: DF60A33037B60951BEAE.mlw
path: /opt/CAPEv2/storage/binaries/22dc1d57032bb2332d059f0218229fd68adf8b137d47ba88b639eb320cd65dbc
crc32: A620A560
md5: df60a33037b60951beae41145cfcd14b
sha1: c925f10f71e93b6739fc1e0068b4038121093dd8
sha256: 22dc1d57032bb2332d059f0218229fd68adf8b137d47ba88b639eb320cd65dbc
sha512: 6fa05db01fa5dfb160e15811064e787dd53b1986dfcec6555fbb1279d46e3602948dfd01db142d6e711ff05894b0bd6184643973d0f243e1c66de59cf48c93b5
ssdeep: 24576:0W4VDcsL9t7LljR/prKItYOL7VxPW3YJdX:0W0t7p517Y8UIJdX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19965BD32E377CF3AD7628A720B218141E17CDA191B67FC66B449276998BCF958700DE3
sha3_384: 6b4f042edc80588c77a6692292ed2bb920ede9e9f9edd1d429f939919a62ee1d57efcf0f5c5bfc5fbf60d0f98f834a11
ep_bytes: e801100000e97ffeffff558bec8b4508
timestamp: 2016-05-09 13:27:24

Version Info:

0: [No Data]

AdWare.Win32.StartSurf.cfgi also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.StartSurf.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zamg.1
FireEyeGeneric.mg.df60a33037b60951
CAT-QuickHealSwbndlr.Dlhelper.V2
ALYacGen:Heur.Mint.Zamg.1
MalwarebytesAdware.IStartSurf
ZillyaAdware.StartSurf.Win32.50668
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053d2701 )
AlibabaAdWare:Win32/StartSurf.a73ecd42
K7GWTrojan ( 0053d2701 )
Cybereasonmalicious.037b60
BitDefenderThetaGen:NN.ZexaF.34294.DzW@aOxjnPmi
CyrenW32/Kryptik.DSV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKQR
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.StartSurf.cfgi
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Kryptik!1.B33C (CLASSIC)
Ad-AwareGen:Heur.Mint.Zamg.1
EmsisoftGen:Heur.Mint.Zamg.1 (B)
ComodoMalware@#1633a1p0fu2bt
DrWebTrojan.Vittalia.17914
McAfee-GW-EditionBehavesLike.Win32.Packed.tm
SophosIStartSurfInstaller (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.Zamg.1
JiangminAdWare.StartSurf.cxsd
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.2801CA4
ArcabitTrojan.Mint.Zamg.1
APEXMalicious
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3PUP/Win32.StartSurf.C2716524
Acronissuspicious
McAfeePacked-FKC!DF60A33037B6
VBA32BScope.Adware.DownloadHelper
TencentMalware.Win32.Gencirc.10cc46de
YandexPUA.StartSurf!84bBd01u0EE
IkarusPUA.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GJJV!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove AdWare.Win32.StartSurf.cfgi?

AdWare.Win32.StartSurf.cfgi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment