Risk

How to remove “RiskTool.Win32.StartPage.qzy”?

Malware Removal

The RiskTool.Win32.StartPage.qzy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.StartPage.qzy virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine RiskTool.Win32.StartPage.qzy?


File Info:

crc32: 717BDDFD
md5: 7ecd4f601d6197f4790bf527771491b8
name: 7ECD4F601D6197F4790BF527771491B8.mlw
sha1: 483ec8c6fd66196710444b2f10ba754d4f916283
sha256: 8a188418787d2d8a12c6ba087af2312c9d6d4f16ea8f502e3cbb04dca73961c5
sha512: 97fb8a5fbd733ebf934366c8b3d8cfa17288ab0100224075fa1b8c60ba8e40116413829cc7c9717dd3b6449562d00ac06f2521fe5453a77b109cf337963cb9bd
ssdeep: 24576:3sXrW59b4pEaDSB4i8gRPQrK5K01gYnzQ:8vp+B4thv0Y
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

RiskTool.Win32.StartPage.qzy also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Packed.29312
MalwarebytesTrojan.MalPack.FlyStudio
K7GWAdware ( 004b87ea1 )
K7AntiVirusAdware ( 004b87ea1 )
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.StartPage.qzy
AlibabaRiskWare:Win32/StartPage.e3fd45bd
SophosGeneric PUA EI (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZedlaF.34266.uv4@ayaXKAmH
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.7ecd4f601d6197f4
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftProgram:Win32/Uwamson.A!ml
GDataWin32.Trojan.PSE.161Z26R
McAfeeArtemis!7ECD4F601D61
VBA32BScope.Trojan.BtcMine
YandexRiskware.StartPage!94kl2xuAbe4
FortinetRiskware/Application

How to remove RiskTool.Win32.StartPage.qzy?

RiskTool.Win32.StartPage.qzy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment