Malware

AdWare.Win32.StartSurf.cgrs (file analysis)

Malware Removal

The AdWare.Win32.StartSurf.cgrs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.cgrs virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
dill.orangessmoke.xyz
potato.giraffegiraffe.website

How to determine AdWare.Win32.StartSurf.cgrs?


File Info:

crc32: 8D762D31
md5: 9f9b9086fac160ff8a54af8e96ff3c3a
name: 9F9B9086FAC160FF8A54AF8E96FF3C3A.mlw
sha1: d0287d79bd77a466592c76083362f88408db1350
sha256: d975ece82bb1d99899f2030918dcfb3b9ecc9847e02d0e374cfae3a60c53555c
sha512: 1e2bf19a065081260d734b756717b7186d5b3e44452e7dfb62d178e9568314a7a7ad899871f593aa93b263c361cad9788c0e23ea4863ac857795e1b83ea94dce
ssdeep: 24576:oE58u9QFNpnkqtoHVAKnpViSjylajVOa12aGT75QRWV:oG8uCFnnkCoHVAupHjXFGT75QRWV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

AdWare.Win32.StartSurf.cgrs also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17914
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1481575
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaAdWare:Win32/StartSurf.c71a7cae
K7GWTrojan ( 0053c4231 )
K7AntiVirusTrojan ( 0053c4231 )
CyrenW32/Kryptik.DSV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKQR
APEXMalicious
AvastWin32:Kryptik-PQT [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.StartSurf.cgrs
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10ca99d7
Ad-AwareGen:Heur.Mint.Zamg.1
SophosIStartSurfInstaller (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.nzW@a0o!AWhi
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.9f9b9086fac160ff
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.xik
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2804EE7
MicrosoftTrojan:Win32/Wacatac.A!rfn
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3Malware/Win32.Generic.C2722082
Acronissuspicious
McAfeePacked-FKC!9F9B9086FAC1
VBA32BScope.Adware.DownloadHelper
MalwarebytesAdware.IStartSurf
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PIT21
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.StartSurf!Cy8l8aPeL+s
IkarusPUA.Dlhelper
FortinetW32/Kryptik.GJJV!tr
AVGWin32:Kryptik-PQT [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.StartSurf.cgrs?

AdWare.Win32.StartSurf.cgrs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment