Trojan

Trojan:Win32/Startpage!pz removal tips

Malware Removal

The Trojan:Win32/Startpage!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Startpage!pz virus can do?

  • A file was accessed within the Public folder.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Startpage!pz?


File Info:

name: CDE11BCB2698F9D0B024.mlw
path: /opt/CAPEv2/storage/binaries/d4c150058956273128f96d0e3385d994309e66366f137abaf5bcf53e6f1f0e89
crc32: 532DD8A8
md5: cde11bcb2698f9d0b0249f25c7e7bb22
sha1: bc48aec4f2b20bf755beb6f220a7fe530e3b5d91
sha256: d4c150058956273128f96d0e3385d994309e66366f137abaf5bcf53e6f1f0e89
sha512: b0c7017e9ad8e64ecb229479539dbce85f7841a0403137ee64d5ef66e339acf0b9e9c5c295741d7d2596a8d41f5997f83c1b514b426363dde66ec187c46323d0
ssdeep: 1536:HD9kNuNMSkRDlALvBYzQn1fskKWIo1K85XAcXoXicXoXen:j94IklALJf0WIo1K85XAc4Sc4On
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC736C123AA0D872E460913148A6C765193DBC331569DA4F7BD43FBE2E327D2CA2B357
sha3_384: e6212258fe8a9f32c0a253fa99226ee6b3bfdc2cb00b388d23741953d1622cfa250d4b865626f8aee0aab19806178a12
ep_bytes: e8e9380000e979feffff6a0c68c8ec40
timestamp: 2010-07-27 18:50:09

Version Info:

0: [No Data]

Trojan:Win32/Startpage!pz also known as:

LionicTrojan.Win32.StartPage.lmCy
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.286027
ClamAVWin.Trojan.Starpage-1
FireEyeGen:Variant.Graftor.286027
CAT-QuickHealTrojan.IgenericRI.S27261887
SkyhighBehavesLike.Win32.Dropper.lm
ALYacGen:Variant.Graftor.286027
Cylanceunsafe
ZillyaTrojan.StartPage.Win32.34501
K7AntiVirusTrojan ( 00196f4e1 )
AlibabaTrojan:Win32/StartPage.f0bfc76b
K7GWTrojan ( 00196f4e1 )
BitDefenderThetaGen:NN.ZexaF.36680.euW@ayUGG7ej
VirITTrojan.Win32.StartPage.ADPP
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/StartPage.NWP
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.StartPage.adpp
BitDefenderGen:Variant.Graftor.286027
NANO-AntivirusTrojan.Win32.StartPage.buant
AvastWin32:Trojan-gen
TencentTrojan.Win32.StartPage.aaz
EmsisoftGen:Variant.Graftor.286027 (B)
BaiduWin32.Trojan.StartPage.ai
F-SecureTrojan.TR/Spy.Agent.79872
DrWebTrojan.StartPage.31245
VIPREGen:Variant.Graftor.286027
TrendMicroTROJ_STARTPA.SMP
SophosMal/Generic-S
JiangminTrojan/StartPage.gam
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Spy.Agent.79872
Antiy-AVLTrojan/Win32.StartPage
KingsoftWin32.Trojan.StartPage.adpp
MicrosoftTrojan:Win32/Startpage!pz
XcitiumTrojWare.Win32.Trojan.Startpage.~adp@256ut2
ArcabitTrojan.Graftor.D45D4B
ViRobotTrojan.Win32.A.StartPage.79872
ZoneAlarmTrojan.Win32.StartPage.adpp
GDataGen:Variant.Graftor.286027
VaristW32/Trojan.MRUN-6125
AhnLab-V3Win-Trojan/Agent.79872.EX
McAfeeGenericRXAA-AA!CDE11BCB2698
TACHYONTrojan/W32.StartPage.79872
VBA32BScope.Adware.Agent
PandaTrj/StartPage.DAW
TrendMicro-HouseCallTROJ_STARTPA.SMP
RisingTrojan.Win32.fedoN.cf (CLASSIC)
YandexTrojan.GenAsa!Q7kaasvHYn4
IkarusTrojan-Spy.Agent
FortinetW32/StartPage.ADPP!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/Startpage!pz?

Trojan:Win32/Startpage!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment