Malware

Should I remove “Troj/Starter-P”?

Malware Removal

The Troj/Starter-P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Starter-P virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Troj/Starter-P?


File Info:

name: 8503A5796AD64F4E65BB.mlw
path: /opt/CAPEv2/storage/binaries/16f44ac52a5942ae9e5bb9d47a535d673dd542002fd077a39acc5f2e6af5ae25
crc32: F7215D93
md5: 8503a5796ad64f4e65bb698d5b8131b2
sha1: 5081432d0ea3d2c758d526184b91dc43654778f2
sha256: 16f44ac52a5942ae9e5bb9d47a535d673dd542002fd077a39acc5f2e6af5ae25
sha512: 99e6c402423d82411c5a84c94df3865e18a6124afc81fa468ee17e246246866389643f13857046a99a383c3a83f84ed8729268f9f40a0663f38814a7d63f23f0
ssdeep: 49152:ONMbQPPK/3dp8GXt2I/9dYoUY5sjBlMJRHQ37auZFBwTpkWcrEYSWasgVrr3jyor:oPceZFBJS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14476298AF655383283A7A1B9657F010BF33B145A8408547CB6ACD8ED1FFD849522BF78
sha3_384: 0e3a85271ce08b71edc785cc1c507f051e4400a448675b40437fcd8b8712e40a26793a932da78bab3b44b50acb92b19a
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-06-11 12:52:22

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: d7cGN.exe
LegalCopyright:
OriginalFilename: d7cGN.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Troj/Starter-P also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Starter.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.FKGP
SkyhighBehavesLike.Win32.Generic.wm
McAfeeGenericRXGK-CT!8503A5796AD6
MalwarebytesTrojan.Starter.MSIL
SangforTrojan.Msil.Starter.V6mw
K7AntiVirusTrojan ( 005342621 )
AlibabaTrojan:MSIL/Starter.80b32d2b
K7GWTrojan ( 005342621 )
Cybereasonmalicious.d0ea3d
ArcabitTrojan.Agent.FKGP
VirITTrojan.Win32.MSIL.QY
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Starter.DC
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.MSIL.Starter.ht
BitDefenderTrojan.Agent.FKGP
EmsisoftTrojan.Agent.FKGP (B)
F-SecureTrojan.TR/Starter.gworm
VIPRETrojan.Agent.FKGP
TrendMicroTROJ_GEN.R002C0PKE23
SophosTroj/Starter-P
IkarusTrojan.MSIL.Starter
JiangminTrojan.MSIL.aoxgr
AviraTR/Starter.gworm
Antiy-AVLTrojan/MSIL.Starter
XcitiumTrojWare.MSIL.Starter.DC@7xi624
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmTrojan.MSIL.Starter.ht
GDataTrojan.Agent.FKGP
VaristW32/A-240503e5!Eldorado
AhnLab-V3Trojan/Win.CT.C4538294
ALYacTrojan.Agent.FKGP
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PKE23
RisingTrojan.Starter!8.2BC (CLOUD)
YandexTrojan.Starter!dx7B8kyBDhU
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Starter.DC!tr
BitDefenderThetaGen:NN.ZemsilF.36680.@p3@ay2BhTc
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Troj/Starter-P?

Troj/Starter-P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment