Trojan

Trojan.VBS.Starter.iz removal guide

Malware Removal

The Trojan.VBS.Starter.iz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VBS.Starter.iz virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Installs OpenCL library, probably to mine Bitcoins
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.VBS.Starter.iz?


File Info:

crc32: D4EFE752
md5: d5b1dc7d4fc4f56ec8427c7887f584b3
name: lock.exe
sha1: 7e479d7a369a2386104ae18685871805d5afe698
sha256: ef27d760c270b45f9c0e024ebd873c228baadd1840212c2ebcc588b119fdd9b7
sha512: 637cdcf646058cb8f31247a3730a6b6d8e4f1a4b03f0e3db6dc4b2b01fb77340ed325a0611e4d9529fc16752237cd060a0fe756dced27aea534ab4cb11935b80
ssdeep: 393216:tVfRPmmUG9pbMr4xwHAIR2lik75yUBzwzn/Wjo3NkZJ:zRumU4pu4KgIRf23zwz/Wi0J
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.VBS.Starter.iz also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42818848
ALYacTrojan.GenericKD.42818848
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42818848
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D28D5D20
ESET-NOD32BAT/CoinMiner.AQQ
APEXMalicious
KasperskyTrojan.VBS.Starter.iz
AvastOther:Malware-gen [Trj]
Ad-AwareTrojan.GenericKD.42818848
EmsisoftTrojan.GenericKD.42818848 (B)
F-SecureHeuristic.HEUR/AGEN.1004703
DrWebVBS.Starter.180
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.tc
FortinetVBS/Agent.CD39!tr
FireEyeGeneric.mg.d5b1dc7d4fc4f56e
SophosGeneric PUA KL (PUA)
IkarusTrojan.BAT.CoinMiner
CyrenW64/Trojan.BODY-1013
AviraHEUR/AGEN.1004703
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (moderate confidence)
MicrosoftTrojan:Win32/Wacatac.D!ml
ZoneAlarmTrojan.VBS.Starter.iz
AhnLab-V3Unwanted/Win32.CoinMiner.C3456414
McAfeeTrojan-Coinminer.l
VBA32Trojan.VBS.Starter
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R007H0CCA20
RisingPUF.CoinMiner!8.4639 (TFE:5:qE59eYqM98)
YandexRiskware.Agent!
GDataTrojan.GenericKD.42818848
AVGOther:Malware-gen [Trj]
PandaTrj/CI.A

How to remove Trojan.VBS.Starter.iz?

Trojan.VBS.Starter.iz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment