Trojan

Trojan:Win32/IStartSurf.PVK!MTB (file analysis)

Malware Removal

The Trojan:Win32/IStartSurf.PVK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/IStartSurf.PVK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests

Related domains:

z.whorecord.xyz
d3vngcy706h320.cloudfront.net
a.tomx.xyz

How to determine Trojan:Win32/IStartSurf.PVK!MTB?


File Info:

crc32: 75E6F825
md5: 9b9663d9052c992d3a78f8f4bed5df9b
name: 1.jpg
sha1: 51b75de0803120a10d28d4d315f4a7932ca2f01f
sha256: f80e1a915dda26713639743a57fecb0acfe9ed7795b5f27ea78ba839a56d75d4
sha512: 535c8c478f973e6b8c70de3b2dbe5f936142a3e50f7522661309adf270ea7d70403de14294b83a3f127f42e92a9e265834e820e3bab3773b9e4cec564c13f283
ssdeep: 24576:bJlh9bDB8shRdrEAbm4zCh0UKElqZAy35RlD720A3tmo8cjCQllubyivuXAlsc:bJYydYAm4zGBKZAy35DD6RtrCQbubCQd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/IStartSurf.PVK!MTB also known as:

MicroWorld-eScanTrojan.ScriptKD.7828
FireEyeGeneric.mg.9b9663d9052c992d
CAT-QuickHealTrojan.Riskware
McAfeeArtemis!9B9663D9052C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.ScriptKD.7828
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9052c9
Invinceaheuristic
F-ProtW32/Agent.BOO.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataWin32.Trojan.Kryptik.OS
Kasperskynot-a-virus:AdWare.Win32.StartSurf.walz
AlibabaTrojan:Win32/IStartSurf.19c92995
NANO-AntivirusTrojan.Win32.SkypeSpam.gznwdj
RisingTrojan.Kryptik!1.C1C6 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.ScriptKD.7828 (B)
ComodoMalware@#2mcr1slhmeo5v
F-SecureTrojan.TR/IStartSurf.Gen
DrWebTrojan.SkypeSpam.11420
ZillyaTrojan.Kryptik.Win32.1937558
TrendMicroTROJ_GEN.R002C0WB720
Trapminemalicious.high.ml.score
SophosIStartSurfInstaller (PUA)
IkarusTrojan.Win32.IStartSurf
CyrenW32/Agent.BOO.gen!Eldorado
JiangminAdWare.StartSurf.cgaa
Avirakmsultimatefree.exe
Antiy-AVLGrayWare[AdWare]/Win32.StartSurf
MicrosoftTrojan:Win32/IStartSurf.PVK!MTB
ArcabitTrojan.ScriptKD.D1E94
SUPERAntiSpywareAdware.IStartSurf/Variant
ZoneAlarmnot-a-virus:AdWare.Win32.StartSurf.walz
AhnLab-V3PUP/Win32.StartSurf.R196040
BitDefenderThetaGen:NN.ZexaF.34126.oHW@aal8gOli
ALYacTrojan.ScriptKD.7828
VBA32Adware.StartSurf
MalwarebytesTrojan.IStartSurf
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HBBV
TrendMicro-HouseCallTROJ_GEN.R002C0WB720
TencentWin32.Adware.Startsurf.Hwcs
YandexPUA.StartSurf!
MAXmalware (ai score=84)
FortinetW32/Kryptik.BVKS!tr
Ad-AwareTrojan.ScriptKD.7828
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Generic/Trojan.Script.3a5

How to remove Trojan:Win32/IStartSurf.PVK!MTB?

Trojan:Win32/IStartSurf.PVK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment