Trojan

Trojan:Win32/Startpage.QW removal guide

Malware Removal

The Trojan:Win32/Startpage.QW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Startpage.QW virus can do?

  • Uses Windows utilities for basic functionality
  • Attempts to modify Internet Explorer’s start page
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify browser security settings
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Startpage.QW?


File Info:

name: C0A1D530592930E0811E.mlw
path: /opt/CAPEv2/storage/binaries/1a11998402ac875be7f7afde90f86552a4dd8878a8edd32b260eceb9b7ee100c
crc32: 3F8E37C4
md5: c0a1d530592930e0811ea3f37a873669
sha1: e05b6e5e2f55ae24174a99321ea30cbef4347ab8
sha256: 1a11998402ac875be7f7afde90f86552a4dd8878a8edd32b260eceb9b7ee100c
sha512: 08f08b7f9b4430a1e1d2c2cdd805c0e78f36d787c4fc872a6cf348db46c30efde69222c7e04abb51927fb4fb64aa36e33acdc3de1d5fdce7d97980aa87bb09a9
ssdeep: 3072:XLF43yOHZPByqZD/lz2ep2BfIYR/vXaHB2++Zreaq7gO7qb:XL63jfl6ep29R3ahEQ7LM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1530412816E8914E1CD590177EC4F81AA5CECDE01C79BC3B6A3BC6278399B218EC5D17C
sha3_384: 5eb3079564675fa04e496ab8d09a599c0a1c3e876ad5dc8f586dd9f5d879a733c74d458a08cfaee7e61454d59b1a8192
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Startpage.QW also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Delf.b!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Dropper.Delf.FD
FireEyeGeneric.mg.c0a1d530592930e0
SkyhighBehavesLike.Win32.Sality.cc
McAfeeArtemis!C0A1D5305929
MalwarebytesMalware.AI.263080290
VIPRETrojan.Dropper.Delf.FD
SangforTrojan.Win32.Delf.buxin
K7AntiVirusTrojan ( 0055e3df1 )
BitDefenderTrojan.Dropper.Delf.FD
K7GWTrojan ( 0055e3df1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.Delf.FL
APEXMalicious
ClamAVWin.Downloader.Banload-1270
KasperskyTrojan-Dropper.Win32.Delf.fl
AlibabaTrojanDropper:Win32/Startpage.f6f5d3c3
NANO-AntivirusTrojan.Win32.IRCbot.crbhdh
RisingTrojan.StartPage!8.B (CLOUD)
EmsisoftTrojan.Dropper.Delf.FD (B)
F-SecureTrojan.TR/Drop.Delf.FD.1
DrWebTrojan.MulDrop.1211
ZillyaDropper.Delf.Win32.14772
TrendMicroTrojan.Win32.STARTPAG.SM
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=99)
GDataTrojan.Dropper.Delf.FD
JiangminTrojanDropper.Delf.fv
WebrootW32.StartPage.Gen
GoogleDetected
AviraTR/Drop.Delf.FD.1
VaristW32/Risk.PIPB-5788
Antiy-AVLTrojan[Dropper]/Win32.Delf
ArcabitTrojan.Dropper.Delf.FD
ZoneAlarmTrojan-Dropper.Win32.Delf.fl
MicrosoftTrojan:Win32/Startpage.QW
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Xema.C210749
BitDefenderThetaGen:NN.ZelphiF.36792.lOWbaWeQFkcc
ALYacTrojan.Dropper.Delf.FD
DeepInstinctMALICIOUS
VBA32BScope.Dropper.Resgen
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.STARTPAG.SM
TencentMalware.Win32.Gencirc.115da72a
YandexTrojan.GenAsa!uPVhaSVSPgg
IkarusBackdoor.Win32.Yobdam
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.FD!tr
AVGWin32:StartPage-LW [Trj]
Cybereasonmalicious.e2f55a
AvastWin32:StartPage-LW [Trj]

How to remove Trojan:Win32/Startpage.QW?

Trojan:Win32/Startpage.QW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment