Malware

Win32/StartPage.AOA removal

Malware Removal

The Win32/StartPage.AOA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/StartPage.AOA virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid

How to determine Win32/StartPage.AOA?


File Info:

name: EB56D76278A4AF666A48.mlw
path: /opt/CAPEv2/storage/binaries/f208076e37595b0abee48f393992154a08d901ebf710901c44e3effc0cfce8a3
crc32: 55860D0A
md5: eb56d76278a4af666a4870ff2898ccdf
sha1: e31e141f4e5b0a1ca8bd15120a1642aa70e8ed0c
sha256: f208076e37595b0abee48f393992154a08d901ebf710901c44e3effc0cfce8a3
sha512: b9823dff1da7b085a9f91de13301a7f1014468bda62bbfcad5a4380e664d039bf5899e94501a5132a95564df1546622b14ef1f931ca792b564c1309fe8040368
ssdeep: 1536:/Z0ULASE5//fp6Yc4Kkvh62sxnG940mOB0pD5NqokO:/Z0+ASE9sz4KO628G96OB0pDvj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107C3B143AA068061F78907B04956FAE9049AAD7C4BD0E5DFF2397E3A69311C31EB315F
sha3_384: faabde512b65f6030d459d322f7df5a4342c2f0ebea7569b0dfc1aafef7b0d97579e5c31d6d4a05300e57d4349063673
ep_bytes: e814060000e96bfdffffff256cd14000
timestamp: 2016-04-07 10:12:01

Version Info:

0: [No Data]

Win32/StartPage.AOA also known as:

MicroWorld-eScanTrojan.GenericKD.71347733
FireEyeTrojan.GenericKD.71347733
SkyhighArtemis
McAfeeArtemis!EB56D76278A4
Cylanceunsafe
VIPRETrojan.GenericKD.71347733
AlibabaTrojan:Win32/StartPage.877d11ac
ArcabitTrojan.Generic.D440AE15
ESET-NOD32Win32/StartPage.AOA
BitDefenderTrojan.GenericKD.71347733
NANO-AntivirusTrojan.Win32.StartPage.ewgqvq
RisingTrojan.StartPage!8.B (TFE:5:MAWewbMRJN)
EmsisoftTrojan.GenericKD.71347733 (B)
ZillyaTrojan.StartPage.Win32.33812
IkarusTrojan.Win32.StartPage
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.BTSGeneric
GoogleDetected
ALYacTrojan.GenericKD.71347733
MalwarebytesGeneric.Malware/Suspicious
FortinetW32/Generic.AC.3438097
DeepInstinctMALICIOUS

How to remove Win32/StartPage.AOA?

Win32/StartPage.AOA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment