Trojan

Trojan:Win32/IStartSurf.LF!MTB removal instruction

Malware Removal

The Trojan:Win32/IStartSurf.LF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/IStartSurf.LF!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

jebena.ananikolic.su
peer.pickeklosarske.ru
teske.pornicarke.com
juice.losmibracala.org

How to determine Trojan:Win32/IStartSurf.LF!MTB?


File Info:

crc32: 6ACAB702
md5: 978e66ccbcaf3596d091fe7c3c21d3ed
name: 978E66CCBCAF3596D091FE7C3C21D3ED.mlw
sha1: 793688b1995a87c035a878ecea066c628d480e7f
sha256: e0fe724f916c1787ea7701872d473b88122a8f0f6f48c78a0ab9df7d76529ee0
sha512: d99452dc2cc89281075570aa2e32c8e23c8b470a7a9b80c4139f3cb40a69469770db2c04d3d4e3059722bd255776273f0e7a35f4fd088a592d1c4726c5589ec8
ssdeep: 3072:7MEWJdd9FAVFO+qT/3RCbXzGgUVTqrfHYxR:wEWJDY78qrg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/IStartSurf.LF!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Packed.21635
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.454631
CylanceUnsafe
ZillyaWorm.Bflient.Win32.10511
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaWorm:Win32/Rimecud.e89c7de4
Cybereasonmalicious.cbcaf3
CyrenW32/Rimecud.R.gen!Eldorado
SymantecW32.Pilleuz!gen19
ESET-NOD32a variant of Win32/Bflient.AC
APEXMalicious
AvastWin32:Morphex [Cryp]
ClamAVWin.Worm.Palevo-27681
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.454631
MicroWorld-eScanGen:Variant.Razy.454631
TencentWin32.Worm.Bflient.Hufu
Ad-AwareGen:Variant.Razy.454631
SophosML/PE-A + Mal/Palevo-A
ComodoTrojWare.Win32.Kryptik.KRJ@38l6ov
BitDefenderThetaGen:NN.ZexaF.34266.hqW@amCJsKni
VIPREWorm.Win32.Palevo.smgl (v)
TrendMicroWORM_PALEVO.SMKV
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
FireEyeGeneric.mg.978e66ccbcaf3596
EmsisoftGen:Variant.Razy.454631 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Palevo.bwyo
AviraTR/Crypt.ZPACK.Gen
KingsoftWorm.Palevo.(kcloud)
MicrosoftTrojan:Win32/IStartSurf.LF!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Koobface
GDataGen:Variant.Razy.454631
AhnLab-V3Win32/Palevo15.worm.Gen
McAfeeGeneric Dropper.yb
MAXmalware (ai score=100)
VBA32BScope.Trojan.MTA.01250
PandaTrj/Rimecud.a
TrendMicro-HouseCallWORM_PALEVO.SMKV
RisingMalware.XPACK!1.657C (CLASSIC)
YandexTrojan.GenAsa!skbO0FpyDp0
IkarusTrojan.Win32.FakeAlert
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Palevo.A!tr
AVGWin32:Morphex [Cryp]
Paloaltogeneric.ml

How to remove Trojan:Win32/IStartSurf.LF!MTB?

Trojan:Win32/IStartSurf.LF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment