Trojan

Should I remove “Trojan:Win32/Startpage!pz”?

Malware Removal

The Trojan:Win32/Startpage!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Startpage!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Startpage!pz?


File Info:

name: C3853FE0918E9086EC85.mlw
path: /opt/CAPEv2/storage/binaries/6e1880c31ddebc67adb9b366bad11b68427cda7ed33ac0175dffb65a941fbca8
crc32: B70E514D
md5: c3853fe0918e9086ec852f2af360ba74
sha1: 0f47ccd3de6eb6ee8e878c2831f73f776eba1419
sha256: 6e1880c31ddebc67adb9b366bad11b68427cda7ed33ac0175dffb65a941fbca8
sha512: cca9f143804078004762a38773dd757afee99b9ca6c98882f5e95135c209913cc759902969e556a471874f7912c04fa9c23fdb6e73662e45c24c57c82055df8a
ssdeep: 768:ifa2l72cNicC8a5R8H+P5wZ4DucGTslDkyq/qbLMDubKMgo9K8Adjl18k:fcNicmUgDh/Zqtubgo9K8Adjl18k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E239F56F30978D5EE06CD3642CBFE1E8328F40394225D81FB903D6EED27C97A82465A
sha3_384: b9ef750d92dfda420b94e5ef9f6d37db2a70db907fda2dd802737820772894db0362b441ff46fbd1510eec5a4e9c579a
ep_bytes: 5589e583ec18c7042402000000ff1594
timestamp: 2010-12-17 04:49:55

Version Info:

0: [No Data]

Trojan:Win32/Startpage!pz also known as:

LionicTrojan.Win32.Oficla.loxg
MicroWorld-eScanGen:Variant.Doina.19116
FireEyeGeneric.mg.c3853fe0918e9086
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Ramnit.pc
McAfeeDownloader-CSV
Cylanceunsafe
ZillyaDownloader.Genome.Win32.28124
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005713a91 )
AlibabaTrojanDownloader:Win32/Startpage.69fa7801
K7GWTrojan ( 005713a91 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Agent.du
VirITTrojan.Win32.Agent2.BXTC
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.RZI
APEXMalicious
TrendMicro-HouseCallTROJ_DROPR.SMIL
ClamAVWin.Trojan.Agent-314499
KasperskyTrojan-Downloader.Win32.Agent.foth
BitDefenderGen:Variant.Doina.19116
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Doina.19116 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader4.62344
VIPREGen:Variant.Doina.19116
TrendMicroTROJ_DROPR.SMIL
SophosMal/Generic-S
MAXmalware (ai score=100)
JiangminTrojanDownloader.Generic.cnr
WebrootTrojan.Dropper
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Risk.XKZV-4886
Antiy-AVLTrojan/Win32.Eruwbi
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Startpage!pz
XcitiumTrojWare.Win32.Startpage.VA@2nwfbd
ArcabitTrojan.Doina.D4AAC
ViRobotTrojan.Win.Z.Doina.49682.B
ZoneAlarmTrojan-Downloader.Win32.Agent.foth
GDataGen:Variant.Doina.19116
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R1628
BitDefenderThetaGen:NN.ZexaF.36802.dyX@a4RhQXfi
ALYacGen:Variant.Doina.19116
TACHYONTrojan/W32.Small.49682.E
VBA32BScope.Trojan.Inject
MalwarebytesMalware.AI.1973644685
PandaTrj/Genetic.gen
RisingTrojan.Win32.StartPage.pya (CLASSIC)
YandexTrojan.GenAsa!NrDBTM7qNwI
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.1857073.susgen
FortinetW32/Oficla.NK!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.0918e9
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Startpage!pz?

Trojan:Win32/Startpage!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment