Malware

JS:Includer-OR [Trj] removal instruction

Malware Removal

The JS:Includer-OR [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What JS:Includer-OR [Trj] virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to identify installed AV products by installation directory
  • Yara detections observed in process dumps, payloads or dropped files

How to determine JS:Includer-OR [Trj]?


File Info:

name: FDA2D33871FB826768B5.mlw
path: /opt/CAPEv2/storage/binaries/bed776a548f1a4c3a6fff0f1d950fd6091e0cd290f3b37bf6c310b994a4d979d
crc32: 565394E6
md5: fda2d33871fb826768b5c0ba30688791
sha1: 0f0ffb5dfccff96a92d9320515ed3cfa44b9417d
sha256: bed776a548f1a4c3a6fff0f1d950fd6091e0cd290f3b37bf6c310b994a4d979d
sha512: 3fc72c3b3defd8af00fe56fd022791e99e527e33048e556eb99674eb5669313f02204c96f5b6150ae4f573e3ebdbfb390b89c7cf62ec6ab79b8ca5c84060db9d
ssdeep: 196608:oys4dV21FXomOqMOTo3Vrp3e+CDxAn3BPx82Qr:owVgF4sOdpDf3hlQr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1678633B12A5053D7F6F146317A5BA5E07E15CC7F40AB2EF533A4BA2A323D0421E2573A
sha3_384: 3fcc918b7e3483469e673beaf16effc88d7a7d49a29f0e3532b77d53f2cce40501f846ecb0d525e6e581ade43289a2a1
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

JS:Includer-OR [Trj] also known as:

BkavW32.Common.96383C18
DrWebAdware.Downware.54
SkyhighBehavesLike.Win32.Dropper.wc
McAfeeArtemis!FDA2D33871FB
AlibabaTrojan:Script/Includer.17e40ab6
VirITAdware.Win32.Downware.CC
AvastJS:Includer-OR [Trj]
JiangminTrojanDownloader.JS.gn
SentinelOneStatic AI – Suspicious PE
AVGJS:Includer-OR [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (W)
alibabacloudTrojan:Multi/Generic

How to remove JS:Includer-OR [Trj]?

JS:Includer-OR [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment