Trojan

Trojan:Win32/Startpage.IP removal

Malware Removal

The Trojan:Win32/Startpage.IP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Startpage.IP virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Startpage.IP?


File Info:

name: 530E4A436276A465F3A8.mlw
path: /opt/CAPEv2/storage/binaries/18615b50c0bae3c5114df9f5ac4626845e9088c59377fa15f534751487569e4f
crc32: 666964A6
md5: 530e4a436276a465f3a8d854c168cdd5
sha1: 0d46c3ad513350bb0261dbd276ab43a91d5502e7
sha256: 18615b50c0bae3c5114df9f5ac4626845e9088c59377fa15f534751487569e4f
sha512: 5a5a604c6eb08d2cde5fbafba128f7f5bad5e556e3f99a66cfeaf2bc4a59009dd9bac2304a8bf3f268c55f74b323862f269b5f8e6d0807caab97ad9d4e9b06e0
ssdeep: 49152:DL6LmZINlOJHZ7fliJAiJqcJUzRkMq5HF3nh/c9uiaEg4u/:DLqYINAJHbQjOzXW9pfsu/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F9533E910A89D95E1D98B70713362B2B32BBA451239C40EB3157F911F1689DBC1F2DF
sha3_384: 105f2982f06b7b4dc77c59dc11241af563f21eb07316fed80394f3f0763e5f765825207bc8a3e036a0f3405a246a5550
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:32

Version Info:

0: [No Data]

Trojan:Win32/Startpage.IP also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.StartPage.4!c
DrWebTrojan.Click1.61237
MicroWorld-eScanDropped:Generic.Dlf.Startpage.B2EB40DF
ClamAVWin.Trojan.Startpage-6849
FireEyeDropped:Generic.Dlf.Startpage.B2EB40DF
CAT-QuickHealTrojan.NSIS.StartPage.A
SkyhighBehavesLike.Win32.Generic.tc
ALYacDropped:Generic.Dlf.Startpage.B2EB40DF
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.StartPage.NRP
K7AntiVirusTrojan ( 004d03e21 )
AlibabaTrojan:Win32/StartPage.319c93f1
K7GWTrojan ( 004d03e21 )
Cybereasonmalicious.d51335
BitDefenderThetaAI:Packer.E5B0005826
VirITTrojan.NSIS.StartPage.Z
SymantecAdware.StartPage
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.NSIS.StartPage.z
BitDefenderDropped:Generic.Dlf.Startpage.B2EB40DF
NANO-AntivirusTrojan.Win32.StartPage.bmhry
AvastNSIS:StartPage-G [Trj]
TencentNsis.Trojan.Startpage.Ojgl
EmsisoftDropped:Generic.Dlf.Startpage.B2EB40DF (B)
F-SecureTrojan:W32/StartPage.ANS
BaiduWin32.Trojan.StartPage.af
VIPREDropped:Generic.Dlf.Startpage.B2EB40DF
TrendMicroTROJ_DLOADR.SM
SophosMal/Generic-S
IkarusTrojan.Win32.StartPage
GDataWin32.Trojan.StartPage.D
JiangminTrojan/StartPage.eai
WebrootW32.StartPage.Gen
GoogleDetected
AviraTR/ATRAPS.Gen2
Antiy-AVLTrojan/Win32.StartPage
KingsoftWin32.Troj.Undef.a
XcitiumApplication.Win32.MeinV.AK@57p4lw
ArcabitGeneric.Dlf.Startpage.B2EB40DF
ZoneAlarmTrojan.NSIS.StartPage.z
MicrosoftTrojan:Win32/Startpage.IP
VaristBAT/StartPage.NSIS
AhnLab-V3Trojan/Win32.StartPage.R1191
McAfeeArtemis!530E4A436276
VBA32TrojanDropper.Agent
Cylanceunsafe
PandaTrj/StartPage.DID
TrendMicro-HouseCallTROJ_DLOADR.SM
RisingTrojan.Win32.StartPage.phv (CLASSIC)
YandexTrojan.GenAsa!EEMkbG2JvF0
MaxSecureTrojan.W32.startpage.z
FortinetW32/Startpage.BD!tr
AVGNSIS:StartPage-G [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/Startpage.IP?

Trojan:Win32/Startpage.IP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment