Malware

Win32/StartPage.ANB removal

Malware Removal

The Win32/StartPage.ANB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/StartPage.ANB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Attempts to modify Internet Explorer’s start page
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/StartPage.ANB?


File Info:

name: B927ECC7EADD60D704E5.mlw
path: /opt/CAPEv2/storage/binaries/58945799feee5c7f10e184a6152b01814ce1a47e037f341c4a08a3aed89d119f
crc32: B65D03BE
md5: b927ecc7eadd60d704e5e29ab97d3229
sha1: bc4c69801c5b600a3d7c95b24601c8ef81a5cbbb
sha256: 58945799feee5c7f10e184a6152b01814ce1a47e037f341c4a08a3aed89d119f
sha512: 9c339886df2eaea3cadbb7e693bfdb128b33c049c6cdd75430d4922f0e56f34d2057ff1ef4cadd9b037b126d4701c83f79ee52af8c6fef22b5be8f0b40f76d0c
ssdeep: 12288:Ltb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSgaThy6A:Ltb20pkaCqT5TBWgNQ7aThy6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187059D1373DE8360C7B25173BA16BB21AEBF7C2506A1F96B2FD4093CE920121565E673
sha3_384: d6e04819f5cfdec01ceb2f8454bdb9a5dc62bcb833e1a5daa26db57bdde8e8aced3775e740b88e18750b53415d634ff1
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2015-04-04 13:58:16

Version Info:

Translation: 0x0809 0x04b0

Win32/StartPage.ANB also known as:

LionicTrojan.Multi.Generic.mgmv
MicroWorld-eScanGen:Trojan.StartPage.0uW@auxZy2pi
FireEyeGen:Trojan.StartPage.0uW@auxZy2pi
McAfeeArtemis!B927ECC7EADD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AlibabaTrojan:Script/StartPage.83a8ffab
Cybereasonmalicious.7eadd6
VirITTrojan.Win32.Generic.COKN
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/StartPage.ANB
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Script.Generic
BitDefenderGen:Trojan.StartPage.0uW@auxZy2pi
NANO-AntivirusTrojan.Win32.StartPage.dwslpp
AvastFileRepMalware
TencentWin32.Trojan.Startpage.Pepj
SophosMal/Generic-S
ComodoMalware@#5dv0gejfxeos
McAfee-GW-EditionBehavesLike.Win32.DownloaderAutoIt.ch
EmsisoftGen:Trojan.StartPage.0uW@auxZy2pi (B)
IkarusTrojan.StartPage
WebrootTrojan.Dropper.Gen
AviraTR/StartPage.Gen
MAXmalware (ai score=82)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Script.Generic
GDataGen:Trojan.StartPage.0uW@auxZy2pi
CynetMalicious (score: 99)
ALYacGen:Trojan.StartPage.0uW@auxZy2pi
TrendMicro-HouseCallTROJ_GEN.R002H0CB322
FortinetW32/StartPage!tr
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/StartPage.ANB?

Win32/StartPage.ANB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment