87130921-60-20220830152356.webstarterz.com: an open folder serving Formbook and XWorm PowerShell scripts, and what to do if one ran

87130921-60-20220830152356.webstarterz.com is a subdomain that URLhaus lists six times in September and October 2026 for PowerShell scripts (crypted.ps1, secured_stub.ps1) and a compressed JavaScript lure named like a parts inquiry. Two scripts are tagged Formbook, one XWorm, and two were still online on 8 October 2026.

A script on a server does nothing until a lure on a Windows PC runs it. If you only saw the name, nothing is proven. If you opened such a file, change your passwords from another device, then scan and clean or reset Windows.

Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a script or attachment that downloads PowerShell files from this webstarterz.com address keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of six URLhaus entries for the webstarterz.com subdomain, PowerShell and JavaScript files, two online and tagged Formbook
The six URLhaus entries we read on 8 October 2026. Our check was a plain request from our server, not a browser visit; it returned an open folder listing.

87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts): summary

TypeA malware download host: an open folder with PowerShell scripts tagged Formbook and XWorm and a compressed JavaScript lure
RiskHigh if the lure or a script ran on your PC: passwords and accounts should be treated as stolen. Low if you only saw the name
SymptomsOften none. Microsoft lists slow performance, changed files and freezing for Formbook; an opened .js or .js.xz attachment is the clearest sign
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove startup entries, and reset Windows if you are not sure
Our check (8 October 2026)One plain request: HTTP 200, an Apache page titled Index of /, an open folder listing
Running since / first seenParent domain registered 21 July 2015; first files reported 9 September 2026, newest 1 October 2026; 2 of 6 online on 8 October
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesNo detection name is known for these exact files. Microsoft detects the family as Trojan:Win32/Formbook
Name87130921-60-20220830152356.webstarterz.com
Domain registered21 July 2015
Evidence6 write-ups by security sites; details still limited
First seen9 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked8 October 2026

Facts checked on 8 October 2026 against the URLhaus data held in our database, RDAP for webstarterz.com, one plain request from our server (no browser), and pages by Microsoft, Malpedia and Seqrite Labs. We did not download or run the files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What this webstarterz.com address is, and what we know about it

87130921-60-20220830152356.webstarterz.com is not a program on your PC. It is a web address on a subdomain of webstarterz.com that URLhaus lists six times, on 9 September and 1 October 2026, for PowerShell scripts and one compressed JavaScript file. Two scripts are tagged Formbook and one XWorm. Two addresses were still online in our copy of the data on 8 October 2026.

The long name looks generated:

  • a number
  • a short number and what reads like a date and time
  • 30 August 2022 at 15:23:56

That pattern suggests an account or site created automatically on a hosting or site builder service, not a name someone chose. This is our reading of the name; we found no page that explains it, and webstarterz.com itself did not resolve when our reading tool tried it.

  1. 1

    What URLhaus lists

    Six file addresses on this host. Three were added on 9 September 2026 at about 18:31 UTC: crypted.ps1 at the top, vic/crypted.ps1, and a file in new/vvv named Alloy, Parts inquiry, ending in .js.xz. Three were added on 1 October at about 15:11 UTC: vic/crypted.ps1 again over plain http, secured_stub.ps1 and new/secured_stub.ps1.

  2. 2

    What the tags mean

    ps1 and powershell mean a Windows PowerShell script. ascii means plain text. xz is a compression format. opendir means the folder could be listed by anyone. Formbook names a Windows malware family that Microsoft detects as Trojan:Win32/Formbook. XWorm names a remote access trojan; it is tagged on the oldest crypted.ps1 only.

  3. 3

    What we could not confirm

    We did not download or run any file, so we cannot tell you which build of Formbook or XWorm the scripts deliver, or where they send data. URLhaus shows tags, not a full analysis. We also do not know who controls this account or whether the host company knows.

  4. 4

    What this means for you

    If you only saw the address in a log or a warning, you are not infected by that alone. The risk is for a Windows PC where someone opened the lure file or where a script already running fetched one of these PowerShell files.

Kind of threat
A web folder that serves PowerShell scripts tagged Formbook and XWorm, plus a compressed JavaScript lure
Where the files are
hxxp://87130921-60-20220830152356[.]webstarterz[.]com/secured_stub.ps1 and /new/secured_stub.ps1 (online on 8 October 2026); older files in /vic/ and /new/vvv/
Parent domain
webstarterz.com, registered 21 July 2015 through GMO Internet Group, Inc. d/b/a Onamae.com, status client transfer prohibited (RDAP, read 8 October 2026)
URLhaus entries
6 file addresses, added 9 September and 1 October 2026; 2 online, 4 offline in our copy of the data
Lure file
A compressed .js file named like a business request for parts, a typical email attachment disguise (our reading of the name)
Platform
Windows. PowerShell and the Formbook and XWorm families are Windows threats; nothing we read points to Mac or phones

What 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts) does on an infected PC

What we checked on 8 October 2026, and what we could not

We sent one plain request to 87130921-60-20220830152356.webstarterz.com from our server on 8 October 2026: no browser, no clicks, no file downloads. The server answered HTTP 200 with a page titled Index of /, served by Apache. That title is what an open folder listing looks like, which matches the opendir tag in URLhaus.

Our check, 8 October 2026

  • An open folder listingThe top of the host answered with a page titled Index of /. Anyone can see which files and folders sit there. We did not open the folders or download anything.
  • What a plain request cannot seeWe did not run any script and did not test the file addresses themselves. An answer from the server says nothing about what the scripts do.
  • Notification requestOur tool found no browser notification request in the answer. A folder listing has no reason to ask for one.
  • URLhaus listingSix PowerShell and JavaScript files; two tagged Formbook and online, one tagged XWorm.
  • Parent domainOur web reading tool could not resolve webstarterz.com itself on 8 October 2026, so we could not read the service's own page or its abuse contact.

Dangerous: treat it as a malware download host The rating comes from the six URLhaus reports, the two files still online and the open folder we saw. Do not open files from this address, and do not run anything that fetches them.

What happened at this address, from the account name to our check

The parent domain is eleven years old and the account name hints at 2022, but every report falls in September and October 2026. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.

  1. 21 July 2015

    webstarterz.com is registered

    RDAP shows the parent domain registered through GMO Internet Group, Inc. d/b/a Onamae.com, a Japanese registrar. RDAP says nothing about the subdomain.

  2. 30 August 2022

    A date inside the name

    The subdomain contains 20220830152356, which reads as 30 August 2022, 15:23:56. If that is a creation time, the account is about four years old. This is our reading, not a fact we could check.

  3. 9 September 2026

    Three files are reported

    At about 18:31 UTC abuse.ch adds crypted.ps1 (tagged xworm), vic/crypted.ps1 and the lure new/vvv/Alloy, Parts inquiry.js.xz, all tagged opendir. All three are offline by our check.

  4. 1 October 2026

    Three more, two tagged Formbook

    At about 15:11 UTC abuse.ch adds vic/crypted.ps1 over http, secured_stub.ps1 and new/secured_stub.ps1. The two secured_stub.ps1 files are tagged Formbook and are still online on 8 October.

    Table of six URLhaus entries for the webstarterz.com subdomain with dates, paths, tags and online status
    All six URLhaus entries as we read them on 8 October 2026. Two Formbook scripts are still online.
  5. 8 October 2026

    Our check

    Our plain request gets an Apache page titled Index of /. The folder is still open.

What the pattern suggests, and what it does not: the operator came back after three weeks and placed new scripts beside the old ones, with names like crypted and secured_stub. That looks like an active, reused account rather than a single upload. It is our reading of the dates, not something any report says.

How a script on this host reaches a PC

A PowerShell file on a web server cannot run on your PC by itself. Something on the PC has to open the lure or fetch the script. We did not run these files; the chain below joins the file names and tags with what Seqrite describes for script loaders in another campaign.

Five steps: an email lure, a JavaScript file runs, PowerShell fetches crypted.ps1 or secured_stub.ps1 from this host, Formbook or XWorm runs, and data leaves the PC
How the files on this host fit a typical chain. The links between steps are our reading, not an observed infection.
  1. 1

    The lure arrives

    The file Alloy, Parts inquiry.js.xz is named like a request from a supplier. Compressing a script in .xz hides its real type from a quick look and from some mail filters. That a person received it by email is our reading of the name; URLhaus does not say how it was sent.

  2. 2

    The script runs

    Inside the .xz archive is a .js file. On Windows a .js file opened from File Explorer is run as a script rather than shown as text. That is why the file ending matters more than the name before it.

  3. 3

    PowerShell fetches the next part

    Seqrite describes the same shape in another campaign: a script decodes a PowerShell command, and PowerShell downloads the next stage from a web address. The crypted.ps1 and secured_stub.ps1 files on this host are the kind of file such a command fetches.

  4. 4

    The final malware is hidden in a genuine program

    In Seqrite's chain the last stage is injected into a genuine Windows program such as msbuild.exe through process hollowing. Malpedia says FormBook carries its own crypter with RunPE behaviour, a related way to run code inside another process.

  5. 5

    The malware sends data out

    Microsoft says Trojan:Win32/Formbook can perform actions of a malicious actor's choice on the device. Which data this build collects is not known to us.

What Formbook and XWorm are, as far as our sources go

We read two reference pages on Formbook for this guide. They confirm the family and how Microsoft detects it, but they do not list its features. We do not repeat lists from pages we did not read.

Sources: Microsoft's Trojan:Win32/Formbook entry and Malpedia's win.formbook page, read 8 October 2026.
QuestionWhat the sources saySource
What is Formbook?A Windows trojan that Microsoft Defender detects as Trojan:Win32/Formbook, published 7 January 2019Microsoft
What can it do?Microsoft says it can perform a number of actions of a malicious actor's choice on the device; its technical details section is emptyMicrosoft
How does it hide?Malpedia says it contains a unique crypter with RunPE behaviour and was first called Babushka CrypterMalpedia
Other namesMalpedia lists XLoader (win.xloader) as an aliasMalpedia
Signs on a PCSlow performance, added or changed files, changed desktop settings, freezing or crashing, less free disk spaceMicrosoft
What is XWorm?URLhaus tags one older script xworm, a remote access trojan name. We read no reference page on XWorm for this guideNot available
Which builds are here?Not known. We did not open the filesNot available

What 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts) can steal or download

What this can cost you

Seeing this address in a log costs nothing. The risks below apply to a Windows PC where the lure was opened or a script from this host ran. They follow from the tags, not from a test of these files.

  • High

    Passwords and accounts

    Formbook is tagged on the two live scripts, and the name stands for a family vendors classify as a stealer. Treat every password typed or saved on the PC as known, and change them from another device.

  • High

    Someone using your PC

    XWorm is tagged on one older script. If it ran, a remote access trojan lets a stranger use the PC while you are signed in.

  • Medium

    Business email and payments

    A lure about a parts inquiry is aimed at people who handle orders. A stolen work mailbox can be used to send fake invoices to your customers.

  • Medium

    More malware on the same PC

    A script loader can fetch anything its operator puts on the server, and this server held more than one family.

  • Low

    Nothing, if you only saw the name

    A name in a block list, a log or a warning is not an infection.

What you may notice, and what you may not

Stealers and loaders are made to stay quiet. The signs below come from Microsoft's Formbook entry and from what the files imply; none is certain.

SignWhat the reports show
A file ending in .js.xz or .js that you openedThe lure on this host has that form. If you opened such a file, assume the chain started
A PowerShell window that flashed and closedPowerShell is how the next stage is fetched. A brief window is common; many builds hide it. This is our reading
Slow performance, freezing or crashingMicrosoft lists these for Trojan:Win32/Formbook
Added or changed files, less free disk spaceMicrosoft lists these too
A Defender detection naming FormbookMicrosoft detects the family as Trojan:Win32/Formbook
Accounts you did not touchLogins from new places, password reset emails or messages sent from your mailbox follow from stolen passwords
Nothing at allThe most common result for a working stealer

How to check the PC for 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts)

If this account or the hosting service is yours

An open folder of scripts on a generated subdomain is typical of a hosting account that was abused or created for abuse. If you run the account or the service, act as if it is in a stranger's hands. This is our advice, not a vendor procedure.

Take the folder listing offline, keep copies of crypted.ps1, secured_stub.ps1 and the .js.xz file for investigators, then remove them. Change the account's passwords and any FTP or deploy keys, look at access logs from early September 2026, and close the account if no customer owns it. After cleaning, ask URLhaus to recheck the listed addresses.

Check your PC before you delete anything

Start with the question that matters: did you open an email attachment about a parts inquiry, or any .js or .js.xz file, around 9 September or 1 October 2026? Or did a firewall or DNS log show a device asking for this address? If yes or not sure, do the checks below. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the network cable. A stealer sends data out, and a remote access trojan needs the connection to be used.

  2. 2

    Find which device asked for the address

    If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question.

  3. 3

    Look at Startup apps

    Open Settings > Apps > Startup and look for names you did not install, especially scripts or programs from your user folder. Write them down; do not delete yet.

  4. 4

    Look for genuine programs that should not be running

    Open Task Manager and look for PowerShell, msbuild.exe or any process with high network or CPU use for no reason. Seqrite names msbuild.exe as a hiding place in a script loader chain. These are real Windows programs, so their presence is not proof.

  5. 5

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for a detection naming Formbook or XWorm, or anything blocked around the dates above. Microsoft says offline scan results also appear here.

  6. 6

    Check Defender exclusions

    In Windows Security > Virus & threat protection > Manage settings > Exclusions, look for folders or file types you did not add. Loaders sometimes add exclusions so they are not scanned. We have no source saying these scripts do that, so a clean list does not clear the PC.

  7. 7

    Check your accounts from another device

    Look at the sign in activity of your email, bank and work accounts, and at the sent folder of your mailbox. This is quicker than any file check.

  8. 8

    A scan helps, but it does not clear the PC

    Microsoft notes that even after Defender removes Formbook, remnant files and system changes can remain, and says to run a full scan with updated definitions. We did not infect a PC, so this plan is our judgement from Microsoft's pages, not a tested result.

How to remove 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts)

How to remove 87130921-60-20220830152356.webstarterz.com

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to 87130921-60-20220830152356.webstarterz.com or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever 87130921-60-20220830152356.webstarterz.com installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The files are PowerShell scripts and a JavaScript lure for Windows, and both tagged families are Windows malware. We found nothing that says they affect anything else.

Your deviceWhat we knowWhat to do
MacMicrosoft and Malpedia describe Formbook as Windows malware; PowerShell lures target WindowsNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source we read mentions these files on iOSNothing to remove. If you typed a password into a page from the email, change it
AndroidNo source we read mentions itNothing to remove for this threat; change passwords if you entered any

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

A stealer sends what it finds within minutes, so cleaning the PC does not undo the theft. Accounts first, from another device, then the PC.

Five steps in order: disconnect the PC, change passwords from another device, run a Defender Offline scan, check startup, the Run key and exclusions, reset Windows if unsure
The order of actions if a script from this host ran. Steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Use your phone or another computer. Start with email, because it resets everything else, then bank, work systems, cloud storage and any shop or supplier portals. Passwords saved in the browser on that PC count as known.

  2. 2

    Sign out other sessions and turn on two step sign in

    Most email and bank accounts let you sign out of all devices and add a second step at sign in. Do both, and check that the recovery email, phone and mail forwarding rules are still yours.

  3. 3

    Warn your customers and suppliers

    If your work mailbox may be stolen, tell regular contacts that you will never change bank details by email. Fake invoices from a real mailbox are the usual next step.

  4. 4

    Run Microsoft Defender Offline

    Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and the scan takes about 15 minutes outside the normal Windows. Results are under Protection history. If BitLocker is on, suspend it first.

  5. 5

    Remove what the check found, with care

    If Startup apps, Task Manager or the exclusions list showed an entry you can tie to the malware, remove it and the file it points to. If you cannot tell, do not guess: the safe answer is the reset below.

  6. 6

    If you are not sure, reset Windows

    In Windows 11 the reset sits at Settings > System > Recovery > Reset this PC. Microsoft says keeping personal files removes apps and settings, and removing everything also deletes your files. Microsoft calls the reset the most disruptive option and says to back up first.

  7. 7

    Restore only documents by hand

    Copy back documents and photos, not programs and not scripts. Delete the .js.xz attachment and any copy of it in Downloads or in your mail program.

  8. 8

    Watch your money and your accounts

    Check card statements and payment logs for a few weeks, turn on alerts, and look at your mailbox rules for forwarding you did not set.

Keep a PC out of this kind of chain

The script on this host is the second step. The first is a file a person opened, so that is where the defence is strongest.

Do

  • Show file endings in File Explorer, so a file named like an inquiry but ending in .js stands out.
  • Treat any .js, .vbs, .hta or .ps1 attachment as an attack, compressed or not.
  • Ask a sender through a known phone number when a request for quotes or parts comes from someone new.
  • Keep Windows and Microsoft Defender updated.
  • Use a password manager and two step sign in, so one stolen password is not enough.
  • Keep a backup of documents on a disk that you unplug.

Don't

  • Do not open archives such as .xz, .zip or .rar from unexpected senders to see what is inside.
  • Do not save passwords in the browser on a shared or work PC that handles email attachments.
  • Do not change your passwords on the PC you suspect.
  • Do not rely on a quiet scan to say that you are safe.

Questions about 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts)

What is 87130921-60-20220830152356.webstarterz.com?

It is a subdomain of webstarterz.com that URLhaus lists for six files: PowerShell scripts named crypted.ps1 and secured_stub.ps1 and a compressed JavaScript file named like a parts inquiry.

Two scripts are tagged Formbook and one XWorm. Two were still online on 8 October 2026, and the host showed an open folder listing. It is not a program on your PC.

Is this address safe to open?

No. Do not open it or download files from it. Our plain request on 8 October 2026 got an Apache page titled Index of /, an open folder.

The danger rating comes from the six URLhaus reports and the two Formbook scripts still online. A quiet or empty page later would not clear it either, because the files can come back under new names.

I opened Alloy, Parts inquiry.js.xz. What now?

Assume the chain started. Disconnect the PC, change your email and other passwords from another device, then run a Microsoft Defender Offline scan and check Startup apps, Task Manager, Protection history and Defender exclusions. If you cannot tie what you find to the malware, reset Windows with Remove everything and restore only documents.

What is Formbook?

Microsoft detects it as Trojan:Win32/Formbook and says it can perform actions of a malicious actor's choice on a device. Malpedia says it carries its own crypter with RunPE behaviour, was first called Babushka Crypter and lists XLoader as an alias. The pages we read do not list its features, so we treat every password on an affected PC as stolen.

What is XWorm?

XWorm is the name of a remote access trojan family. URLhaus tags only the oldest crypted.ps1 on this host with it, and that file is offline.

We read no reference page on XWorm for this guide, so we do not list its features here. If a Defender detection on your PC names XWorm, follow the same plan as for Formbook.

I saw this address in my firewall or DNS log. Am I infected?

Not necessarily. It means a device on your network asked for it, and a person does not usually type such a name. Find the device, disconnect it, and do the checks on this page.

Change account passwords from another device. If the log shows a request for a .ps1 file, treat that device as infected until checked, and run a Microsoft Defender Offline scan on it.

How do I remove Formbook from Windows?

Change your passwords from another device first. Then run a Microsoft Defender Offline scan from Windows Security, Virus and threat protection, Scan options, followed by a full scan with updated definitions as Microsoft advises.

Remove startup entries you can tie to the malware. If you are not sure, reset Windows. We did not test this on an infected PC.

What is webstarterz.com, and is the whole domain malicious?

RDAP shows webstarterz.com registered on 21 July 2015 through a Japanese registrar. The long generated subdomain looks like one account on a hosting or site builder service; that is our reading.

URLhaus lists this one subdomain. We could not read the service's own page, so we cannot say anything about other accounts on it.

Does this affect Mac, iPhone or Android?

We found nothing that says so. The files are PowerShell scripts and a JavaScript lure for Windows, and Formbook is Windows malware.

On a Mac or a phone there is nothing to remove; if you typed a password into a page from the email, change it. Forward the email to your IT team or delete it.

Will Fortect remove 87130921-60-20220830152356.webstarterz.com?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For 87130921-60-20220830152356.webstarterz.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: 87130921-60-20220830152356.webstarterz.com (Formbook, XWorm, PowerShell scripts)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year