Trojan

Trojan:Win32/Startpage!pz removal tips

Malware Removal

The Trojan:Win32/Startpage!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Startpage!pz virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Startpage!pz?


File Info:

name: 55B8D252737D27E45F61.mlw
path: /opt/CAPEv2/storage/binaries/bb440f7b86468d72089f15ff3ef805ec3817177434cb3644095f011ccf5e7a56
crc32: ACCB5BE1
md5: 55b8d252737d27e45f61105ee528764f
sha1: 6e29011f72e90b280a8cb9ef750cd35084557ac3
sha256: bb440f7b86468d72089f15ff3ef805ec3817177434cb3644095f011ccf5e7a56
sha512: 6a2ce3d63f01b8c2e816efdf84d4ad76e98d5f7d1c1d72f5598138ffda718d2d0b6d8b06b23757dc23103b3952685962e4fe44ae311a2e79a16029c8c43ca00a
ssdeep: 1536:V3cpyORJLuB4P4AJJv4Romu/J/xKzi+5uhOIi:V3c1fP4AJJv45mKO+Upi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D753CF1633D0C8A7DAA652725D77CBBAE3FBDE10162046476B206F7F3C31182A8275D6
sha3_384: d27a08c3d19b075cd2aa51602a233e4cda3250cac6270ef1c940540e49f3a3700b6d3df9fdd05802c7eecbf76f756469
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:27

Version Info:

0: [No Data]

Trojan:Win32/Startpage!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.StartPage.lojX
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.Startpage.10.5D5E8967
FireEyeDropped:Generic.Startpage.10.5D5E8967
CAT-QuickHealTrojan.NSIS.Startpage.DV
SkyhighStartPage-NQ
McAfeeArtemis!55B8D252737D
Cylanceunsafe
ZillyaDropper.StartPage.Win32.2265
K7AntiVirusTrojan ( 005658de1 )
AlibabaTrojanDropper:Win32/StartPage.960afc25
K7GWTrojan ( 005658de1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitGeneric.Startpage.10.5D5E8967
VirITTrojan.Win32.Generic.KZR
SymantecAdware.Links
ESET-NOD32NSIS/StartPage.AP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.NSIS-32
KasperskyTrojan-Dropper.Win32.StartPage.dvq
BitDefenderDropped:Generic.Startpage.10.5D5E8967
NANO-AntivirusTrojan.Nsis.Dropper.ddffbj
AvastNSIS:StartPage-AK [Drp]
TencentWin32.Trojan-Dropper.Startpage.Osmw
EmsisoftDropped:Generic.Startpage.10.5D5E8967 (B)
BaiduNSIS.Trojan.StartPage.b
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.StartPage.44510
VIPREDropped:Generic.Startpage.10.5D5E8967
TrendMicroTROJ_STARTP.SMHU
Trapminesuspicious.low.ml.score
SophosMal/StartP-AM
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Startpage.Gen
VaristW32/Zlob.AF.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/NSIS.StartPage.ap
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.Agent.giyt@3cwvfp
MicrosoftTrojan:Win32/Startpage!pz
ZoneAlarmTrojan-Dropper.Win32.StartPage.dvq
GDataDropped:Generic.Startpage.10.5D5E8967
GoogleDetected
AhnLab-V3Dropper/Win32.StartPage.C57737
VBA32Trojan.StartPage
ALYacDropped:Generic.Startpage.10.5D5E8967
MAXmalware (ai score=100)
PandaAdware/StartPage.DKV
TrendMicro-HouseCallHV_ZYX_BH01027E.TOMC
YandexNSIS.Startpage.Gen.20
IkarusTrojan-Dropper.Win32.StartPage
MaxSecureDropper.StartPage.dvq
FortinetW32/StartPage.BX!tr.NSIS
AVGNSIS:StartPage-AK [Drp]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Startpage!pz?

Trojan:Win32/Startpage!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment