Trojan

Trojan.StartPage.ZSC information

Malware Removal

The Trojan.StartPage.ZSC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.StartPage.ZSC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Likely virus infection of existing system binary

How to determine Trojan.StartPage.ZSC?


File Info:

name: 636E90865C45D3F868FE.mlw
path: /opt/CAPEv2/storage/binaries/17565578115477c692d183d5a2cafdfe545cb5b8a72ef509afb4cf38cd5d1fcc
crc32: F5498261
md5: 636e90865c45d3f868fe6061634ebbab
sha1: e30b742190f5c2047b4afd2f6f25f3e538c29c41
sha256: 17565578115477c692d183d5a2cafdfe545cb5b8a72ef509afb4cf38cd5d1fcc
sha512: 398de33f6d918b23e3e6edfb8028e3286eb9dcb546823abdf611fd1b1e3efbfa2daef892b395c33ab24bedb6b68455eb31dcb453c9efa609d5dacc1677c6ca7d
ssdeep: 12288:3ghm8FELJ17wCpNPjIqxuuECGDUg8Zy/cLONpB6c:3km8eHLO7Bx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B705F849569A81C2F0735C3434A5F7A31E3BB43B5AC48E732319670AEB5F90A165EF0E
sha3_384: ee9054af19020af3bb1d2bf0e4684018f795a370723a0d3390b6a135fda7a561653485f7ad73fd0cb13ad520383566ce
ep_bytes: 558bec6aff68988f4100683c6a400064
timestamp: 2009-12-17 13:45:06

Version Info:

Comments:
CompanyName: 桌面伴侣
FileDescription: DeskMate
FileVersion: 1, 0, 0, 1
InternalName: DeskMate
LegalCopyright: Copyright ? 2009
LegalTrademarks:
OriginalFilename: DeskMate.exe
PrivateBuild:
ProductName: 桌面伴侣 DeskMate
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan.StartPage.ZSC also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.FakeAV.10171
MicroWorld-eScanTrojan.StartPage.ZSC
FireEyeGeneric.mg.636e90865c45d3f8
McAfeeGenericRXFN-RM!636E90865C45
CylanceUnsafe
ZillyaDropper.Inegery.Win32.95
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDropper:Win32/Inegery.0ce488ac
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaGen:NN.ZexaF.34182.0m1@a070cCeb
VirITTrojan.Win32.Generic.DF
CyrenW32/StartPage.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BPJ
TrendMicro-HouseCallTROJ_AGENT_005925.TOMB
Paloaltogeneric.ml
ClamAVWin.Dropper.Agent-296415
KasperskyTrojan-Dropper.Win32.Inegery.sd
BitDefenderTrojan.StartPage.ZSC
NANO-AntivirusTrojan.Win32.Drop.ikjbg
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Trojan-gen
TencentTrojan.Win32.StartPage.abn
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_AGENT_005925.TOMB
McAfee-GW-EditionGenericRXFN-RM!636E90865C45
EmsisoftTrojan.StartPage.ZSC (B)
IkarusTrojan-Downloader.Agent2
JiangminTrojanDropper.Inegery.q
WebrootTrojan/Win32.Startpage
AviraTR/StartPage.OH
Antiy-AVLTrojan/Generic.ASMalwS.5259
MicrosoftPWS:Win32/Zbot!ml
ViRobotDropper.A.Inegery.859143
GDataTrojan.StartPage.ZSC
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.StartPage.R3301
ALYacTrojan.StartPage.ZSC
MAXmalware (ai score=80)
VBA32BScope.Trojan.StartPage
MalwarebytesMalware.AI.701582869
APEXMalicious
RisingTrojan.Win32.StartPage.nzq (CLOUD)
YandexTrojan.GenAsa!EBMb6TJsRt4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Dropper.Inegery.cq
FortinetW32/Inegery.A!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.65c45d
PandaTrj/Genetic.gen

How to remove Trojan.StartPage.ZSC?

Trojan.StartPage.ZSC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment