Malware

What is “UDS:AdWare.Win32.StartSurf”?

Malware Removal

The UDS:AdWare.Win32.StartSurf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:AdWare.Win32.StartSurf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine UDS:AdWare.Win32.StartSurf?


File Info:

name: 7690352569B980BB3838.mlw
path: /opt/CAPEv2/storage/binaries/21331d7376df4b867fbccb7e4589e8612bb254e98d92d750e670ca63e1fb61e9
crc32: AF40A67A
md5: 7690352569b980bb3838c8037f46a8a9
sha1: 451abea6b5aae8bc5362d771e8394abc8318a96a
sha256: 21331d7376df4b867fbccb7e4589e8612bb254e98d92d750e670ca63e1fb61e9
sha512: 53c383ba2c15204932eff877be47a86b03649d9194d168caff7f9223f629f28e1fadfaa1a082cdeecd90ade7aef7833f3473b9645d724a32a8fe41bb8ecd6fbf
ssdeep: 24576:fY2T6ncopSJf1mVyNZcesxtY43sGtT8HpIR5kuUHxIKOH:dLgxf/xUR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192D5333CE957F18BC76B15BBDC94B86E4158EBF90E0148335A7D091CD7E18C4E42A2BA
sha3_384: d9576b355be425b6709123f2a24e24d3a0047f9224d02692563ab84bf2758f44ef36387ce03b7e2ceb1b6fd6aa8d107c
ep_bytes: 558bec81eca80000008b45e82b45f489
timestamp: 2015-06-12 00:32:56

Version Info:

LegalCopyright: ©Htaidinini miomhehyru
OriginalFilename: wielsaetnoo.exe
ProductName: WIELSAETNOO
InternalName: WIELSAETNOO.EXE
FileVersion: 2.8.7.1
ProductVersion: 2.8.7.1
CompanyName: ©Htaidinini miomhehyru
Translation: 0x0409 0x04e4

UDS:AdWare.Win32.StartSurf also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Vittalia.17867
MicroWorld-eScanGen:Heur.Mint.Zamg.1
FireEyeGeneric.mg.7690352569b980bb
SkyhighPacked-FKC!7690352569B9
McAfeePacked-FKC!7690352569B9
Cylanceunsafe
ZillyaTrojan.Generic.Win32.269959
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005410101 )
AlibabaTrojan:Win32/Kryptik.51ff3ad2
K7GWTrojan ( 005410101 )
Cybereasonmalicious.6b5aae
ArcabitTrojan.Mint.Zamg.1
BitDefenderThetaGen:NN.ZexaF.36744.PE0@aq8xieni
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GMFB
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:UDS:AdWare.Win32.StartSurf.gen
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
RisingTrojan.Kryptik!1.B33C (CLASSIC)
EmsisoftGen:Heur.Mint.Zamg.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
VIPREGen:Heur.Mint.Zamg.1
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Crypt
JiangminTrojan.Generic.ctuwn
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLGrayWare/Win32.Unwaders
KingsoftWin32.Troj.StartSurf.gen
XcitiumMalCrypt.Indus!@1qrzi1
MicrosoftProgram:Win32/Unwaders.C!rfn
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataGen:Heur.Mint.Zamg.1
VaristW32/Trojan.WRBN-9104
AhnLab-V3Trojan/RL.Generic.R242598
VBA32BScope.Adware.Puwaders
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TencentMalware.Win32.Gencirc.10bd08d9
YandexTrojan.Agent!h/bqFu7S9fE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.GMFB!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove UDS:AdWare.Win32.StartSurf?

UDS:AdWare.Win32.StartSurf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment