Risk

How to remove “Startpage.Riskware.Hijacker.DDS”?

Malware Removal

The Startpage.Riskware.Hijacker.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Startpage.Riskware.Hijacker.DDS virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Startpage.Riskware.Hijacker.DDS?


File Info:

name: 79742BC67F122ADD9614.mlw
path: /opt/CAPEv2/storage/binaries/244e27558cc72c2282fb76b5dd2804294143bffb69ecfd48a7b6e7d0f9ad37f2
crc32: 01D84A6B
md5: 79742bc67f122add961437cd04a3fd24
sha1: 3dc971d5d2eebb32203de2f1d27e5f3d6f4d5702
sha256: 244e27558cc72c2282fb76b5dd2804294143bffb69ecfd48a7b6e7d0f9ad37f2
sha512: c54f9c15f79d2102267957f8e2ed4eff4bf1a4af0d1fd6d63ded5204c8ee7d525a66347e7c6d51d5e34ec2075b5e8f10abab25f990e6bcc93ced8eeaa68934a0
ssdeep: 3072:iWF+TcJgWSlpEUxfQwPqUYDJbcyQR4fK+zofDGz6/G:Z+T3lIwPbYnQOz6/G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9E38D3A34D1C8FBC14100314DA1DBBAB7F9E9340D729B5323999F4D6D3E966C6272A2
sha3_384: 039739f5f4e9729d3d0b2001ac28e8f67bc92fad7a938fbc09be99f7366139040b441a9b433a4c5f302e42a1f5a619b9
ep_bytes: 558bec6aff6810bf41006864a3400064
timestamp: 2009-12-10 01:26:26

Version Info:

0: [No Data]

Startpage.Riskware.Hijacker.DDS also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.79742bc67f122add
CAT-QuickHealTrojan.IgenericPMF.S27331193
SkyhighStartPage-LN
McAfeeStartPage-LN
VIPREGen:Variant.StartPage.1
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005352941 )
AlibabaTrojan:Win32/StartPage.f0d719ec
K7GWTrojan ( 005352941 )
Cybereasonmalicious.67f122
BaiduWin32.Trojan.StartPage.an
VirITTrojan.Win32.StartPage.COMH
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/StartPage.NSE
APEXMalicious
ClamAVWin.Trojan.Startpage-1796
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.StartPage.1
NANO-AntivirusTrojan.Win32.StartPage.inrcr
MicroWorld-eScanGen:Variant.StartPage.1
TencentTrojan.Win32.StartPage.aav
SophosMal/Generic-S
F-SecureTrojan.TR/StartPage.NX
DrWebTrojan.StartPage.44935
ZillyaTrojan.StartPage.Win32.10512
TrendMicroTROJ_STRTPGE.SMR
EmsisoftGen:Variant.StartPage.1 (B)
IkarusTrojan.Win32.StartPage
JiangminTrojan/Generic.dpva
WebrootTrojan:Win32/Sapade
GoogleDetected
AviraTR/StartPage.NX
Antiy-AVLTrojan/Win32.StartPage.nse
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.StartPage.~JH1@1r3tbm
ArcabitTrojan.StartPage.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.StartPage.1
VaristW32/StartPage.H.gen!Eldorado
AhnLab-V3Win-Trojan/StartPage2.Gen
ALYacGen:Variant.StartPage.1
MAXmalware (ai score=99)
DeepInstinctMALICIOUS
VBA32Trojan.StartPage
MalwarebytesStartpage.Riskware.Hijacker.DDS
TrendMicro-HouseCallTROJ_STRTPGE.SMR
RisingTrojan.Win32.StartPage.nxz (CLASSIC)
YandexTrojan.GenAsa!NOBhRYRjD50
MaxSecureTrojan.Malware.1728868.susgen
FortinetW32/StartPage.LY!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan:Win/StartPage.NSE

How to remove Startpage.Riskware.Hijacker.DDS?

Startpage.Riskware.Hijacker.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment