Trojan

Trojan:Win32/Startpage!I information

Malware Removal

The Trojan:Win32/Startpage!I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Startpage!I virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to create or modify a Browser Helper Object
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Startpage!I?


File Info:

name: AB75A41CC44236545E37.mlw
path: /opt/CAPEv2/storage/binaries/327ba85e0dc1d174e1aad20453dcd7f71dde483e7c8896ff64885a1c6094c026
crc32: 36883079
md5: ab75a41cc44236545e3753e889a8e550
sha1: 0d22837c89abe93049a611115bd6d017e82a5a38
sha256: 327ba85e0dc1d174e1aad20453dcd7f71dde483e7c8896ff64885a1c6094c026
sha512: 99e914d85d15ae3fdff99ce688d968a72cc1d17866f847752a63373a39d9ddce3863a7301b0ef490b6f5abfd65711bd6f40b0115a7b95a16860fa490b637cc2f
ssdeep: 12288:QyzSqWgPr9+ZuurGZTt7HGzXey7aTGwQqhzVRM:QMSq/PcTKt7iXdCTVVW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EAF47D26F1E08433D1772B3C9C5BA6989C3EBD116E38B80A7BE41D4C4E3968179352E7
sha3_384: 0fd18f03b3c4aaea8726d44830096370fe26dadee9951921bb33b1b9b38ba50b16f930ab2cc07ac67d0ed539caba1501
ep_bytes: 558bec83c4f0535657b8fc444200e85d
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Startpage!I also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Pasta.lKom
MicroWorld-eScanGeneric.Startpage.5.F7657B30
ClamAVWin.Dropper.Detected-9963321-0
FireEyeGeneric.mg.ab75a41cc4423654
SkyhighBehavesLike.Win32.PWSLegMir.bh
McAfeeGeneric StartPage.as
Cylanceunsafe
ZillyaTrojan.Pasta.Win32.2469
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/Pasta.9f18a7ff
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.c89abe
BitDefenderThetaAI:Packer.C7AD1A671C
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/BHO.NUN
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Pasta.dlh
BitDefenderGeneric.Startpage.5.F7657B30
NANO-AntivirusTrojan.Win32.BHO.edfffz
AvastWin32:StartPage-ADH [Trj]
TencentMalware.Win32.Gencirc.10b3b4c1
EmsisoftGeneric.Startpage.5.F7657B30 (B)
F-SecureTrojan.TR/BHO.Gen
DrWebTrojan.StartPage.46349
VIPREGeneric.Startpage.5.F7657B30
TrendMicroTROJ_PASTA.BE
SophosMal/BHO-J
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.StartPage.C
JiangminTrojan/Pasta.ix
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/BHO.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Pasta
KingsoftWin32.Troj.ClickerBHOT.xa.761432
XcitiumTrojWare.Win32.Pasta.SB@1iacgq
ArcabitGeneric.Startpage.5.F7657B30
ViRobotTrojan.Win32.A.Pasta.766952
ZoneAlarmTrojan.Win32.Pasta.dlh
MicrosoftTrojan:Win32/Startpage.gen!I
VaristW32/Risk.YCNK-5630
AhnLab-V3Trojan/Win32.Pasta.R5675
VBA32BScope.Trojan-PSW.Game.7
ALYacGeneric.Startpage.5.F7657B30
MalwarebytesBHO.Trojan.Clicker.DDS
PandaTrj/StartPage.DAW
TrendMicro-HouseCallTROJ_PASTA.BE
RisingTrojan.Win32.StartPage.nfw (CLASSIC)
YandexTrojan.GenAsa!cxWqh8xFO2I
IkarusTrojan-Dropper.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/StartPage.FVU!tr
AVGWin32:StartPage-ADH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Startpage!I?

Trojan:Win32/Startpage!I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment