Malware

AdWare.Win32.StartSurf.creh malicious file

Malware Removal

The AdWare.Win32.StartSurf.creh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.creh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

dill.orangessmoke.xyz
potato.giraffegiraffe.website

How to determine AdWare.Win32.StartSurf.creh?


File Info:

crc32: 70D20DD3
md5: 5d4bbbec4320d2aeb211ba35862574e2
name: 5D4BBBEC4320D2AEB211BA35862574E2.mlw
sha1: d75bc43d226598ed7ba12e9f8d5a776e06477130
sha256: 5f83b9b4f2b209cd512d74c7a0302171784f903ee8e1c75f830bde43c7d368ec
sha512: a386412e9b7ab3fa9ce5f56fc77dfeb0fff724cb36c4e0fd26a9d85817bb8d91a5e559d6d6f6c0a825c0a254b778dbcde1293092f6476d0fdc434f30bdb4487b
ssdeep: 24576:23p6p5MsoGaGO2q7BQ8sDE0b8E/ReIErFH:Mp6p2Gax28+vwuReIEr1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

AdWare.Win32.StartSurf.creh also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00564f7e1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealSwbndlr.Dlhelper.V2
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.52302
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaAdWare:Win32/StartSurf.cca62d42
K7GWTrojan ( 00538f291 )
Cybereasonmalicious.c4320d
CyrenW32/Kryptik.DSV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKQR
APEXMalicious
AvastWin32:Kryptik-PQT [Adw]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.creh
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10cc6105
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/EncPk-ABL
BitDefenderThetaGen:NN.ZexaF.34294.6qW@a84Nitki
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.5d4bbbec4320d2ae
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.ije
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.28146D0
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Mint.Zamg.1
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3PUP/Win32.BundleInstaller.R237893
Acronissuspicious
McAfeePacked-FKC!5D4BBBEC4320
MAXmalware (ai score=98)
VBA32BScope.Adware.StartSurf
MalwarebytesAdware.IStartSurf
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
IkarusPUA.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.DWTQ!tr
AVGWin32:Kryptik-PQT [Adw]
Paloaltogeneric.ml

How to remove AdWare.Win32.StartSurf.creh?

AdWare.Win32.StartSurf.creh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment