Trojan

Should I remove “Trojan:Win32/Starter.P”?

Malware Removal

The Trojan:Win32/Starter.P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Starter.P virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics

How to determine Trojan:Win32/Starter.P?


File Info:

crc32: D23E8D9D
md5: f65bf2aa6474b75b2acf1b3d2f5b4b6f
name: F65BF2AA6474B75B2ACF1B3D2F5B4B6F.mlw
sha1: dbe45db2c02a8b5da1a6bd8a99d697ef774b36e3
sha256: dd69d722b50cda88a614d5a2e40b654be7ebe4ae4a4c77c21eaaec3f3b8e659c
sha512: 3a83beced0353fb5a6eaac337b1e4075dba286ed9b44fa6b6c736618b2d72cadded8c3acd5dff527f662e489f5b4ed2c3fbc8beaa16485a4fa701d9768a7cbfb
ssdeep: 6144:sW+7+eMqShN15Y1Y1rpieVBMwkJnQy7AVJfzMvfnVgXrJ5VbWD3niK/3wZdYZ:sR101u1Y1weVewyYFAfQrJ7bW79/3r
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: John T. Haller
InternalName: OpenOffice.org Writer Portable
FileVersion: 1.4.0.0
CompanyName: PortableApps.com
LegalTrademarks: PortableApps.com is a Trademark of Rare Ideas, LLC.
Comments: Allows OpenOfficeWriter to be run from a removable drive. For additional details, visit PortableApps.com/OpenOfficePortable
ProductName: OpenOffice.org Writer Portable
ProductVersion: 1.4.0.0
FileDescription: OpenOffice.org Writer Portable
OriginalFilename: OpenOfficeWriterPortable.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Starter.P also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.4209610
FireEyeGeneric.mg.f65bf2aa6474b75b
McAfeeArtemis!F65BF2AA6474
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 004b8aa51 )
BitDefenderTrojan.GenericKD.4209610
K7GWTrojan ( 004b8aa51 )
Cybereasonmalicious.a6474b
SymantecPacked.NSISPacker!g3
ESET-NOD32Win32/Kovter.D
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Troldesh-7764148-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kovter.c8a22701
NANO-AntivirusTrojan.Nsis.Kovter.eikqxz
Ad-AwareTrojan.GenericKD.4209610
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1102526
DrWebTrojan.Kovter.297
ZillyaTrojan.Kovter.Win32.4437
TrendMicroRansom_NSISRansom.SM001
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.fc
EmsisoftTrojan.Win32.FileCoder (A)
AviraHEUR/AGEN.1102526
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Starter.P
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D403BCA
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AhnLab-V3Trojan/Win32.Cerber.R189553
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.4209610
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.4209610
MalwarebytesTrojan.PasswordStealer
PandaTrj/CI.A
TrendMicro-HouseCallRansom_NSISRansom.SM001
TencentWin32.Trojan.Generic.Ecjz
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.ID!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM42.1.0432.Malware.Gen

How to remove Trojan:Win32/Starter.P?

Trojan:Win32/Starter.P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment