Trojan

Should I remove “Trojan:Win32/Startpage!pz”?

Malware Removal

The Trojan:Win32/Startpage!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Startpage!pz virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the shellcode patterns malware family
  • Deletes executed files from disk
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Startpage!pz?


File Info:

name: A7B8F5964097C49CCBC5.mlw
path: /opt/CAPEv2/storage/binaries/18955ec5b79207cab82aadebd9df0198cb7a38d157b2a78d63158a920708ee43
crc32: D4794F89
md5: a7b8f5964097c49ccbc5c7ce9d88c362
sha1: f48deeafd919eaf9e64fe47b9937bd647fda2f17
sha256: 18955ec5b79207cab82aadebd9df0198cb7a38d157b2a78d63158a920708ee43
sha512: 480c34a78139400ae313f138ac585785d04f70508f8d21e1a6703ddd08ea3b137e94a9dc57e813b9f6cb34bc671b40158db806a01ce2a61c0ee496253fc18d5a
ssdeep: 768:Oe3PFaDVyOQgljLDKRJyM3BmsHzSB4us/wJJapg4RoSMZeUZB/OezfdwX9B+k2DY:V3cpyORJLuB4P4AJJv4Romu/XlM6k2DY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B443BF1633C5C8B7E9264631597BCB3AE7B7EA00132046476B689F7F2C31183DD3A596
sha3_384: f0d3fee3f6d1f975b2fd59ac666c2eb2750a9013bf01ee3bcbc7cf61a36ab822c8f3dbdcaca9cbdf11b56c5d5299c226
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:27

Version Info:

0: [No Data]

Trojan:Win32/Startpage!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.StartPage.lne9
MicroWorld-eScanDropped:Generic.Startpage.10.D535AC22
FireEyeDropped:Generic.Startpage.10.D535AC22
CAT-QuickHealTrojan.NSIS.Startpage.DV
SkyhighBehavesLike.Win32.StartPage.qh
McAfeeArtemis!A7B8F5964097
MalwarebytesMalware.AI.3696523613
VIPREDropped:Generic.Startpage.10.D535AC22
SangforPUP.Win32.StartPage.Vvor
K7AntiVirusTrojan ( 005658de1 )
AlibabaTrojanDropper:Win32/StartPage.8ec1aaf7
K7GWTrojan ( 005658de1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32NSIS/StartPage.AP
APEXMalicious
ClamAVWin.Trojan.NSIS-27
KasperskyTrojan-Dropper.Win32.StartPage.dvp
BitDefenderDropped:Generic.Startpage.10.D535AC22
NANO-AntivirusTrojan.Nsis.Startpage.uumin
AvastNSIS:StartPage-AK [Drp]
EmsisoftDropped:Generic.Startpage.10.D535AC22 (B)
BaiduNSIS.Trojan.StartPage.e
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop2.61374
TrendMicroTROJ_STARTP.SMHR
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.StartPage
MAXmalware (ai score=100)
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Zlob.AF.gen!Eldorado
Antiy-AVLTrojan/NSIS.StartPage.at
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/Startpage!pz
XcitiumMalware@#1ftcty02abga6
ArcabitGeneric.Startpage.10.D535AC22
ViRobotDropper.A.StartPage.57058.QW
ZoneAlarmTrojan-Dropper.Win32.StartPage.dvp
GDataDropped:Generic.Startpage.10.D535AC22
CynetMalicious (score: 99)
AhnLab-V3Dropper/Win32.StartPage.R11293
VBA32Trojan.StartPage
ALYacDropped:Generic.Startpage.10.D535AC22
Cylanceunsafe
PandaAdware/StartPage.DKV
TrendMicro-HouseCallHV_ZYX_BH01027E.TOMC
YandexNSIS.Startpage.Gen
SentinelOneStatic AI – Suspicious PE
FortinetW32/StartPage.BX!tr.NSIS
AVGNSIS:StartPage-AK [Drp]
Cybereasonmalicious.64097c
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/StartPage.AP

How to remove Trojan:Win32/Startpage!pz?

Trojan:Win32/Startpage!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment