Trojan

Trojan.StartPage.2oLfaCt6Cqkb (B) removal instruction

Malware Removal

The Trojan.StartPage.2oLfaCt6Cqkb (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.StartPage.2oLfaCt6Cqkb (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.StartPage.2oLfaCt6Cqkb (B)?


File Info:

name: C0D52A602FB71BDF83D9.mlw
path: /opt/CAPEv2/storage/binaries/a1ed83b3b24040d6a88cf96bfd6996f5cefee85031f30ef731d4673a36631b54
crc32: 2BC8B745
md5: c0d52a602fb71bdf83d9f19dfb1f0451
sha1: 49d25ecfe9cf9bfdcfcd91dca5558609a9f41a57
sha256: a1ed83b3b24040d6a88cf96bfd6996f5cefee85031f30ef731d4673a36631b54
sha512: 28613da26790d665ead4b27c55a05ca9b7d80bcaa6bb8f1f4e8257430dadfa3d279980b0bc83217c036ea2fbae7e1f5a167a1e2f2d895fcf7b4706a29e6a4408
ssdeep: 49152:q+Hdmc+KRpFni/+5Z0giqkg3YaVaKuSFZP4CaiunXz6a7ScIQkxzyEi4sVX0D45k:q6X3pFni/+ycd31VaKuSFB5aPnXz6xcs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102D5334E0792B62DF8A61E70522EF8D8464E705209167CB85D0BC9E85773DD7F6C2B0B
sha3_384: 53dcd5cfb33bc88bee38cac1473ed8e7afc83767008ec55a7b8d22de421a9a781cd1256de23df4d41d85bf80067230c1
ep_bytes: 60be001052008dbe0000eeff5783cdff
timestamp: 2022-02-04 12:25:47

Version Info:

FileVersion: 10.18.1.0
FileDescription: MySkin LOL
ProductName: MySkin
ProductVersion: 10.18.1.0
CompanyName: sky
LegalCopyright: sky的版权所有
Comments: MySkin LOL
Translation: 0x0804 0x04b0

Trojan.StartPage.2oLfaCt6Cqkb (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.StartPage1.60617
MicroWorld-eScanGen:Trojan.StartPage.2oLfaCt6Cqkb
FireEyeGeneric.mg.c0d52a602fb71bdf
CAT-QuickHealTrojan.GenericRI.S25624699
ALYacGen:Trojan.StartPage.2oLfaCt6Cqkb
MalwarebytesMalware.AI.1752481740
BitDefenderGen:Trojan.StartPage.2oLfaCt6Cqkb
K7GWAdware ( 005071f51 )
K7AntiVirusAdware ( 005071f51 )
BitDefenderThetaGen:NN.ZexaF.34212.2oLfaCt6Cqkb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Bulz-9889678-0
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
RisingTrojan.Convagent!8.12323 (RDMK:cmRtazp+s7xHJn8rPdvHNXCgNKn0)
Ad-AwareGen:Trojan.StartPage.2oLfaCt6Cqkb
SophosMal/Agent-AVP
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Trojan.StartPage.2oLfaCt6Cqkb (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Script.auat
AviraTR/Spy.Gen3
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Script/Phonzy.B!ml
ArcabitTrojan.StartPage.2oLfaCt6Cqkb
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.gen
GDataWin32.Trojan.PSE.5LSHNI
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R444729
Acronissuspicious
VBA32Adware.Agent
PandaTrj/GdSda.A
TencentMalware.Win32.Gencirc.10d01578
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.02fb71
AvastScript:SNH-gen [Trj]

How to remove Trojan.StartPage.2oLfaCt6Cqkb (B)?

Trojan.StartPage.2oLfaCt6Cqkb (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment