Malware

What is “AdWare.Win32.StartSurf.cntu”?

Malware Removal

The AdWare.Win32.StartSurf.cntu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.cntu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
dill.orangessmoke.xyz
potato.giraffegiraffe.website
a.tomx.xyz

How to determine AdWare.Win32.StartSurf.cntu?


File Info:

crc32: 363F3E81
md5: 05a4d6ed5a4623ae09e4bfd123ce908a
name: 05A4D6ED5A4623AE09E4BFD123CE908A.mlw
sha1: 247bdc2989cfc976d328d4b74d76dfc0c6fa7686
sha256: 2159cc9bc61acdbca221ce2dd3bfc43737b5f7b9661d2df4fdcbca447948fbc9
sha512: a2fd5f5737286093898f515fbd117bae2187b2a664869a7e5740f25e533bb16b04afbf8af2f858d4a4cb1407af4934c6de02bc14cac495226eb4ddee3987c0f7
ssdeep: 24576:NKM1JvRZTuQb2Oi5FNx/VIWyj89vxPUMmanUz:NKgDZa6AzXpxsMu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

AdWare.Win32.StartSurf.cntu also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053c4231 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17914
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.51534
SangforTrojan.Win32.Save.a
AlibabaMalware:Win32/km_2ca61.None
K7GWTrojan ( 0053c4231 )
Cybereasonmalicious.d5a462
CyrenW32/Kryptik.DSV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKQR
APEXMalicious
AvastWin32:Kryptik-PQT [Adw]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.cntu
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10ca9b80
Ad-AwareGen:Heur.Mint.Zamg.1
SophosIStartSurfInstaller (PUA)
BitDefenderThetaGen:NN.ZexaF.34294.qvW@aa7JR0bi
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.05a4d6ed5a4623ae
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.axon
AviraTR/Crypt.XPACK.Gen4
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.280E106
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Mint.Zamg.1
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3Packed/Win.FKC.R446557
Acronissuspicious
McAfeePacked-FKC!05A4D6ED5A46
MAXmalware (ai score=100)
VBA32BScope.Adware.DownloadHelper
MalwarebytesAdware.IStartSurf
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.StartSurf!P4lrdaJ7kIo
IkarusPUA.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CFOO!tr
AVGWin32:Kryptik-PQT [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.StartSurf.cntu?

AdWare.Win32.StartSurf.cntu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment