Malware

Should I remove “StartPage.5”?

Malware Removal

The StartPage.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What StartPage.5 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine StartPage.5?


File Info:

name: D20B0CAC5D788131D629.mlw
path: /opt/CAPEv2/storage/binaries/a921c74b43bd9db488479f7d97b77d77395d343d6be3dd89415a2eec527fde5d
crc32: EB3C5852
md5: d20b0cac5d788131d629a2af62fcceca
sha1: dcbe6cf9da2a3f570be37d8c129723d54707d826
sha256: a921c74b43bd9db488479f7d97b77d77395d343d6be3dd89415a2eec527fde5d
sha512: 87e2dc48f768196c073b50e103e5f942df01d7d4797a1cc21198e05c2ee7ed2a7e60099618b9c24beee14ee26a250ef5573944fc595c92417efc475d50c4d727
ssdeep: 12288:WO9xBymEFyzcYH7vwGZEgQNkT8HZOqJlXy1:WObcHwb4N2YZnlXa
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T18BB47D22F6E18433D1732A7C9C6B63AC983A7E103D7898467BE81D4C5F39681756B393
sha3_384: e9985127f9fef6406df4ae84b9989f8197bc789b539c16adbe1c1579fb564ad44897a27f3bc06b1fbf88dadeba90a6d4
ep_bytes: 558bec83c4c4b87ca24600e818bef9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

StartPage.5 also known as:

LionicTrojan.Win32.Delf.lV2h
MicroWorld-eScanGen:Variant.StartPage.5
FireEyeGeneric.mg.d20b0cac5d788131
SkyhighGenericRXPP-NT!D20B0CAC5D78
McAfeeGenericRXPP-NT!D20B0CAC5D78
VIPREGen:Variant.StartPage.5
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/StartPage.7191138e
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.StartPage.5
VirITTrojan.Win32.Generic.DBQ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/StartPage.NTV
CynetMalicious (score: 100)
ClamAVWin.Trojan.Bho-7163
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.StartPage.5
NANO-AntivirusTrojan.Win32.StartPage.fiixuh
AvastWin32:StartPage-AJL [Trj]
TencentWin32.Trojan.ATRAPS.Lflw
EmsisoftGen:Variant.StartPage.5 (B)
F-SecureTrojan.TR/Rogue.4123820
ZillyaTrojan.BHO.Win32.9187
TrendMicroTROJ_SPNR.35DG13
SophosMal/Generic-S
IkarusTrojan.Win32.BHO
JiangminTrojan/BHO.kvs
WebrootW32.Dynamer.Gen
VaristW32/Risk.QDAF-4582
AviraTR/Rogue.4123820
Antiy-AVLTrojan/Win32.BHO
KingsoftWin32.Trojan.Generic.a
XcitiumMalware@#psjz65lc9jnw
MicrosoftTrojan:Win32/Dynamer!dtc
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.StartPage.5
GoogleDetected
AhnLab-V3Trojan/Win32.StartPage.R22171
VBA32Trojan.BHO
ALYacGen:Variant.StartPage.5
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SPNR.35DG13
RisingTrojan.Win32.StartPage.pmn (CLASSIC)
YandexTrojan.GenAsa!sF0eNP6V9a0
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1523551.susgen
FortinetW32/BHO.ALFL!tr
AVGWin32:StartPage-AJL [Trj]
DeepInstinctMALICIOUS

How to remove StartPage.5?

StartPage.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment