Malware

Win32/StartPage.AMR (file analysis)

Malware Removal

The Win32/StartPage.AMR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/StartPage.AMR virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/StartPage.AMR?


File Info:

name: B3FE299F09E417D9CCD7.mlw
path: /opt/CAPEv2/storage/binaries/9b33b82b08ce74e2c5f9cb75e32eece38acd1c90e0f20759430867e358abf4d4
crc32: AA86BB17
md5: b3fe299f09e417d9ccd77cf1784658b6
sha1: c328267eaf4ec5f18e379651bc9f10d5ffc8b1a6
sha256: 9b33b82b08ce74e2c5f9cb75e32eece38acd1c90e0f20759430867e358abf4d4
sha512: 95e3835e253b02415f894af5d5c0fcd3acbf6e6f0c6acbf6baece635aaf7688c87e859eda3523a460b9a517485a73c46f5b287e2cb993301518266d612bc2cf8
ssdeep: 3072:MFqmotgegZwrDNKzg3IKuKtNUBLmRQGSrKOn5drM0emHg9T5N:yqmzZZwvWQIKLOLASH5Lkn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1D3080033F3AA30E9A7933A06EB7BED273DFB258BA169C753403A16C7709D45535A52
sha3_384: bc05ab309684705f73cb2b31cd2842155fd62e51a26dd0a2e87bbbf2f318c28369737b77cc712daa831d8483f7387397
ep_bytes: e8d3300000e97ffeffff558bec518d45
timestamp: 2015-08-28 11:51:43

Version Info:

CompanyName: InternetSecurity Inc
FileDescription: Amazing security tool
FileVersion: 1.0.0.8
InternalName: WIT
LegalCopyright: Copyright 2015 InternetSecurity Inc, All rights reserved.
OriginalFilename: WIT.exe
ProductName: WebInstaller
ProductVersion: 1.0.0.8
Translation: 0x0409 0x04b0

Win32/StartPage.AMR also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.452930
FireEyeGeneric.mg.b3fe299f09e417d9
MalwarebytesMalware.AI.256852099
BitDefenderThetaGen:NN.ZexaF.36196.iy0@aqVN7xki
VirITTrojan.Win32.Startpage.XYT
CyrenW32/Trojan.WLIO-3049
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/StartPage.AMR
APEXMalicious
CynetMalicious (score: 99)
BitDefenderGen:Variant.Zusy.452930
NANO-AntivirusTrojan.Win32.StartPage.dwqznn
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Startpage.ka
EmsisoftGen:Variant.Zusy.452930 (B)
F-SecureHeuristic.HEUR/AGEN.1306257
VIPREGen:Variant.Zusy.452930
McAfee-GW-EditionGenericRXVY-CJ!B3FE299F09E4
Trapminemalicious.moderate.ml.score
GDataWin32.Trojan.PSE.J54LKO
AviraHEUR/AGEN.1306257
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.BTSGeneric
ArcabitTrojan.Zusy.D6E942
MicrosoftPUA:Win32/Privitize
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5395059
ALYacGen:Variant.Zusy.452930
TACHYONTrojan/W32.Agent.137728.TZ
Cylanceunsafe
RisingTrojan.StartPage!8.B (TFE:5:GYLIW9rJg3L)
IkarusPUA.Techsnab
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Wacatac.B!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/StartPage.AMR?

Win32/StartPage.AMR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment