Risk

RiskTool.Win32.StartPage.bn information

Malware Removal

The RiskTool.Win32.StartPage.bn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.StartPage.bn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine RiskTool.Win32.StartPage.bn?


File Info:

name: 47F012411944FA74E5D7.mlw
path: /opt/CAPEv2/storage/binaries/99fdd0803189f08191bb17f852c667772af2934823badd3c98d3420f97a0f9da
crc32: B4C8DD09
md5: 47f012411944fa74e5d75e7689f6fdfe
sha1: 076bf7eac8f25f75127c6193d312f2206125ecf5
sha256: 99fdd0803189f08191bb17f852c667772af2934823badd3c98d3420f97a0f9da
sha512: 25d1c942e47d0b2687b66f56e9d7f85e330f8e8d55dcaaefc157239541b7aca40ca9a1a9852ab34d9f5af2a6c6b8614bd8f42285975e3bbdaf20b29744855be0
ssdeep: 24576:olN82T6nJ4UBfB7VPN3om93HQXIqJrEUMOmjPUj5bL:oY4q7VVYm9KRJrEUnmjP0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B55AF92F68380B2D525153059BA673AA9399A110F34DBC3B3A4DD7F7E322D1D93630B
sha3_384: f9802b31b83974bdc5a7eed2c6adff38cb0524cb3a8496673b2d8df30cfe5211aebf811fd2aa18ccd395629395151cbe
ep_bytes: 558bec6aff6840555100683c5b470064
timestamp: 2015-06-30 00:37:28

Version Info:

0: [No Data]

RiskTool.Win32.StartPage.bn also known as:

LionicRiskware.Win32.StartPage.1!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.47f012411944fa74
CAT-QuickHealRisktool.Startpage.A4
McAfeeGenericR-DZH!47F012411944
MalwarebytesBitcoinMiner.Trojan.Miner.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_90% (D)
BaiduWin32.Trojan.FlyStudio.py
VirITTrojan.Win32.Agent5.ACKZ
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/QQWare.M
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9820446-0
Kasperskynot-a-virus:RiskTool.Win32.StartPage.bn
NANO-AntivirusTrojan.Win32.StartPage1.dtufaj
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b130f9
DrWebTrojan.StartPage1.16655
ZillyaTrojan.QQWare.Win32.585
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
AviraTR/QQWare.1355776
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Skeeyah.A!bit
GoogleDetected
AhnLab-V3Malware/Gen.Generic.C1133029
BitDefenderThetaGen:NN.ZexaF.36308.srW@aCEd13cb
VBA32BScope.Trojan.Downloader
RisingMalware.Undefined!8.C (TFE:5:rzivXLW7xwU)
YandexTrojan.GenAsa!uhwJYpU6XSc
IkarusTrojan.Win32.QQWare
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove RiskTool.Win32.StartPage.bn?

RiskTool.Win32.StartPage.bn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment