Malware

AdWare.Win32.StartSurf.cvja malicious file

Malware Removal

The AdWare.Win32.StartSurf.cvja is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.cvja virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

Related domains:

dill.orangessmoke.xyz
potato.giraffegiraffe.website

How to determine AdWare.Win32.StartSurf.cvja?


File Info:

name: 38808E8821EAF6221837.mlw
path: /opt/CAPEv2/storage/binaries/22dff413ba96ac315d0016d7487fb60550afa014c6865f58b89b6df400aabcff
crc32: 5E8C97A4
md5: 38808e8821eaf62218372c547996e880
sha1: 608e52bb6be3b15f52436b62325daa47cd840c68
sha256: 22dff413ba96ac315d0016d7487fb60550afa014c6865f58b89b6df400aabcff
sha512: 232983900befd3b92e8cd7a703c4375071a957511d904c82a61d028db5354d5c0652f680e8d3ade85b9207138c0bacdc02d4792369c8bfde0a35bfe84aac2766
ssdeep: 24576:tG1A4DWKvF3ch4bQXKmpw0ltKB5gvmTii1P:tx4DWK9sh4bOK4w0mSg/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13525122639CDA43DD82319B25864C7BE03AA7C6B0A7F09D732C07E2F353D061966576E
sha3_384: 2fb660b9d6be984cb891762481ae86e420380b58bed3716e43f3b62df4ea3a6ddd5356734e8a19f80e4f3d827f0322db
ep_bytes: e801100000e97ffeffff558bec8b4508
timestamp: 2015-05-25 07:48:26

Version Info:

0: [No Data]

AdWare.Win32.StartSurf.cvja also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.StartSurf.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zamg.1
FireEyeGeneric.mg.38808e8821eaf622
McAfeePacked-FKC!38808E8821EA
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00538f291 )
AlibabaAdWare:Win32/StartSurf.e2b6ca92
K7GWTrojan ( 00538f291 )
Cybereasonmalicious.821eaf
BitDefenderThetaGen:NN.ZexaF.34294.7qW@amwTr6ei
CyrenW32/S-6c560421!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKQR
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.StartSurf.cvja
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusRiskware.Win32.StartSurf.fifill
AvastFileRepMalware
RisingTrojan.Kryptik!1.B33C (CLASSIC)
Ad-AwareGen:Heur.Mint.Zamg.1
SophosTroj/Wonton-PG
ZillyaAdware.StartSurf.Win32.53631
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.Zamg.1
JiangminAdWare.StartSurf.jib
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2818C18
ArcabitTrojan.Mint.Zamg.1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2738844
Acronissuspicious
VBA32Trojan.Vittalia
ALYacGen:Heur.Mint.Zamg.1
MalwarebytesAdware.IStartSurf
TencentMalware.Win32.Gencirc.10cbc97d
YandexTrojan.GenAsa!sInMiEAoufs
IkarusPUA.Dlhelper
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GIST!tr
AVGFileRepMalware
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove AdWare.Win32.StartSurf.cvja?

AdWare.Win32.StartSurf.cvja removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment