Malware

AdWare.Win32.StartSurf.cwxc (file analysis)

Malware Removal

The AdWare.Win32.StartSurf.cwxc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.StartSurf.cwxc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
dill.orangessmoke.xyz
potato.giraffegiraffe.website

How to determine AdWare.Win32.StartSurf.cwxc?


File Info:

crc32: 02A03B38
md5: fb774dde4f93935e7716f93e029e3265
name: FB774DDE4F93935E7716F93E029E3265.mlw
sha1: 955ea77d77c6741c4acf67049904c29b8f8f8592
sha256: dd9ceab99a1e9c4a97a126b6c9df178b5153e9b10519d9b0ed860e8a9328bbd8
sha512: f47805a00c6604a3379568d26e6b78d2d3b83e7359643aabd27e66b0e83f7f6f115f81a456da6db2d3d0a0f9444bf62fd8f49fecbe5d86142684854aac927703
ssdeep: 12288:JTtDnhMipS61O7PCCLsk1CeqzzF5UO20UP2kaxK2UZ2avQEsmu2ZSKB7Cj7Dav0:aiEQwauQeqzsXP2kl2YoEsZ2rB76D1c
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

AdWare.Win32.StartSurf.cwxc also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00538f291 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.13656
CynetMalicious (score: 100)
CAT-QuickHealSwbndlr.Dlhelper.V5
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.54511
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/StartSurf.beae9083
K7GWTrojan ( 00538f291 )
Cybereasonmalicious.e4f939
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKRJ
APEXMalicious
AvastWin32:Evo-gen [Susp]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.cwxc
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusTrojan.Win32.Kryptik.fifezv
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10cb5da0
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/Generic-R + Troj/Wonton-PG
ComodoMalware@#37pojot9sajiy
BitDefenderThetaAI:Packer.AB47905E1E
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.fb774dde4f93935e
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.jid
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.281B1E1
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Mint.Zamg.1
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3Malware/Win32.Generic.C2737274
Acronissuspicious
McAfeePacked-FKC!FB774DDE4F93
MAXmalware (ai score=99)
VBA32BScope.AdWare.StartSurf
MalwarebytesAdware.IStartSurf
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexTrojan.GenAsa!2uPoup85BFs
IkarusPUA.Dlhelper
FortinetW32/Kryptik.GIST!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove AdWare.Win32.StartSurf.cwxc?

AdWare.Win32.StartSurf.cwxc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment