Malware

What is “VirTool:Win32/Startpage!rfn”?

Malware Removal

The VirTool:Win32/Startpage!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Startpage!rfn virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine VirTool:Win32/Startpage!rfn?


File Info:

name: B3C95719A3E1944AE8AD.mlw
path: /opt/CAPEv2/storage/binaries/4d44bff9b5c1e0fe2f3ec2c00d6257476fb7355d77599e2420434d1aafd009bc
crc32: D8F09782
md5: b3c95719a3e1944ae8ad7af4f4b48820
sha1: 615c94f154da8f0da0e42f931b74aafbe4406c92
sha256: 4d44bff9b5c1e0fe2f3ec2c00d6257476fb7355d77599e2420434d1aafd009bc
sha512: a5364651c3a993dc3cb5395c67ba763421d4dfa7fb96fa5adf4181b1b20c4119aedab8c82a42cddf1fa1f41eb278d5f645248f88bc0376500036a9041651a820
ssdeep: 12288:5X8BkNgKYUz4EN6BSYNwYQRmvOocHp+IZVrEWlut:F8BkN8C6r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185D4E841669A91C3F03254783896B7A31E3BF4376EC48F72222E570AEB6ED06115EF4D
sha3_384: f1179712b75150af352f375573e912e04e9a8e673426355fc6c2527ae234d21874fe54985a66504dac164efba476fd68
ep_bytes: 558bec6aff68988f410068ec6a400064
timestamp: 2009-12-17 09:10:22

Version Info:

Comments:
CompanyName: 快快捷桌面秀
FileDescription: 一款桌面辅助美化工具
FileVersion: 2.0.1.1
InternalName: Mac Tool
LegalCopyright: Mac Copyright
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: 快快捷桌面秀
ProductVersion: 2.0.1. 1
SpecialBuild:
Translation: 0x0804 0x04b0

VirTool:Win32/Startpage!rfn also known as:

MicroWorld-eScanGen:Variant.Zusy.458945
CAT-QuickHealTrojanDropper.Injector.B4
ALYacGen:Variant.Zusy.458945
MalwarebytesGeneric.Trojan.Injector.DDS
VIPREGen:Variant.Zusy.458945
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0055e3991 )
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.9a3e19
CyrenW32/Injector.K.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.BPJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Inegery.cr
BitDefenderGen:Variant.Zusy.458945
NANO-AntivirusTrojan.Win32.Inegery.csezo
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10bde86a
EmsisoftGen:Variant.Zusy.458945 (B)
F-SecureTrojan.TR/StartPage.OH
DrWebTrojan.FakeAV.10170
ZillyaDropper.Inegery.Win32.63
McAfee-GW-EditionBehavesLike.Win32.Generic.ht
FireEyeGeneric.mg.b3c95719a3e1944a
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Zusy.458945
JiangminTrojan/Generic.yz
AviraTR/StartPage.OH
MAXmalware (ai score=85)
Antiy-AVLTrojan[Dropper]/Win32.Inegery
XcitiumTrojWare.Win32.TrojanDropper.Inegery.~as@1v7xnb
ArcabitTrojan.Zusy.D700C1
ZoneAlarmTrojan-Dropper.Win32.Inegery.cr
MicrosoftVirTool:Win32/Startpage!rfn
GoogleDetected
AhnLab-V3Dropper/Win.Inegery.R559196
Acronissuspicious
McAfeeGenericRXGK-ZP!B3C95719A3E1
TACHYONTrojan-Dropper/W32.Inegery.602161
VBA32TrojanDropper.Inegery
Cylanceunsafe
PandaTrj/Genetic.gen
RisingAdWare.Win32.Undef.fkm (CLASSIC)
YandexTrojan.GenAsa!EBMb6TJsRt4
IkarusTrojan-Downloader.Agent2
MaxSecureTrojan.Malware.1861627.susgen
FortinetW32/Inegery.A!tr
BitDefenderThetaGen:NN.ZexaF.36196.Kq1@aSAOBldb
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove VirTool:Win32/Startpage!rfn?

VirTool:Win32/Startpage!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment