Trojan

Trojan:Win32/Startpage.LQ (file analysis)

Malware Removal

The Trojan:Win32/Startpage.LQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Startpage.LQ virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Startpage.LQ?


File Info:

name: F2B33E8E29BCB2838ED5.mlw
path: /opt/CAPEv2/storage/binaries/4236df30357c1b752a1c9475c81228ef45b6c58e408c92f0755a09bf78152037
crc32: 1C68EFD2
md5: f2b33e8e29bcb2838ed5b0be9ca7894a
sha1: 7a459463bc0c033c60ae811110a658b2fe61cd68
sha256: 4236df30357c1b752a1c9475c81228ef45b6c58e408c92f0755a09bf78152037
sha512: 6808457ec6bd7af703c61435b2c3a982541d3e5b1a48c77cbb5e4bee3cb73cb468a6e856d8c7c7121167e3ce215577b6ba293cfe69816c2143e27a2fc4ecb04a
ssdeep: 3072:43c1fP4AJJI3288+l80hHs/DDGHqhH5D1/OyrGuoaBacaW:iOPj035lvhM/DDGHqhH//quTkPW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BE3B0163AC644B7E56612702EFB9621E3BA6E1015714347F39C6E2F3FB11C296293E3
sha3_384: c2867beac946f4dd3c52ba674ee3c9aa38e9e01229eb60bf8080923d7472a9b4e924505f99a671b508866c6d37748e1d
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:27

Version Info:

0: [No Data]

Trojan:Win32/Startpage.LQ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.StartPage.4!c
MicroWorld-eScanGen:Variant.Nemesis.23502
FireEyeGen:Variant.Nemesis.23502
SkyhighBehavesLike.Win32.Dropper.ch
ALYacGen:Variant.Nemesis.23502
Cylanceunsafe
ZillyaTrojan.Agent.Win32.128146
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanClicker:VBS/StartPage.5b2eb46a
K7GWSpyware ( 0016b5311 )
K7AntiVirusSpyware ( 0016b5311 )
VirITTrojan.Win32.MulDrop1.CJWJ
SymantecTrojan.ADH
Elasticmalicious (high confidence)
ESET-NOD32VBS/TrojanClicker.Agent.NAK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.VBS.Agent.km
BitDefenderGen:Variant.Nemesis.23502
NANO-AntivirusTrojan.Script.Agent.bfhwis
AvastNSIS:Malware-gen [Trj]
TencentIrc.Trojan.Ls_gencirc.Wmhl
EmsisoftGen:Variant.Nemesis.23502 (B)
BaiduVBS.Trojan.StartPage.cw
F-SecureMalware.VBS/Agent.kk.2999
DrWebTrojan.MulDrop1.41817
VIPREGen:Variant.Nemesis.23502
TrendMicroTROJ_STARTP.SMN
SophosMal/Generic-S
GDataGen:Variant.Nemesis.23502
JiangminTrojan/VBS.dd
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/JS.StartPage.g
KingsoftWin32.Troj.Unknown.a
XcitiumMalware@#oj4zdu3t3402
ArcabitTrojan.Nemesis.D5BCE
ZoneAlarmTrojan.VBS.Agent.km
MicrosoftTrojan:Win32/Startpage.LQ
VaristVBS/Agent.ET
AhnLab-V3Trojan/Win32.StartPage.C1969553
McAfeeArtemis!F2B33E8E29BC
MAXmalware (ai score=100)
VBA32Trojan-Clicker.VBS.Agent.nak
MalwarebytesMalware.AI.686681032
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_STARTP.SMN
RisingTrojan.Win32.StartPage.puk (CLASSIC)
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetVBS/Agent.KM!tr
AVGNSIS:Malware-gen [Trj]
Cybereasonmalicious.3bc0c0
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Startpage.LQ?

Trojan:Win32/Startpage.LQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment