Trojan

Script.Trojan.38726 information

Malware Removal

The Script.Trojan.38726 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Script.Trojan.38726 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • A cryptomining command was executed
  • Anomalous binary characteristics

How to determine Script.Trojan.38726?


File Info:

name: C3A33948F35D5BFB750F.mlw
path: /opt/CAPEv2/storage/binaries/81aa73d9058f277305d10deaaed7140e041bca44b38bb63b1d31ee5d71f1c2ce
crc32: 83C0CA63
md5: c3a33948f35d5bfb750f1ed436142afb
sha1: 09aa218d1dddbf62580596c1b85e03c17db223d5
sha256: 81aa73d9058f277305d10deaaed7140e041bca44b38bb63b1d31ee5d71f1c2ce
sha512: 2f5867788af3e35d6a2e5a74e3c454db25d010199dd62a7aa28be8c642d231351daf135fa52fa8bb03dab4d2ed1499a14ac64a7fa1c78a239405ef95017123f3
ssdeep: 196608:vg69AUzVnRu6XTmg3Xorj+sz6NcfU+gX8pG6AMH8xXptXqg4crbcQvw:vgWZD3Xo52sU0iXDqNcvc6w
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AA633E0BFF5BCB5E550523170D6B03C2BE61B1CCF094893AB4EEA027DA15C6A2F5A45
sha3_384: eb99631d0af471fa79ee38b4d770c38f290b070f6dea827ea2654ea27bce9205e3ea8096a3508974f2af48f8db0d0e2f
ep_bytes: 558bec6aff6870c4410068c095410064
timestamp: 2012-12-31 00:38:51

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

Script.Trojan.38726 also known as:

LionicRiskware.Script.BitMiner.1!c
Elasticmalicious (high confidence)
FireEyeTrojan.Sesfix.3
CAT-QuickHealScript.Trojan.38726
McAfeeArtemis!C3A33948F35D
CylanceUnsafe
SangforCoinMiner.BAT.Agent.ab
K7AntiVirusAdware ( 0055be151 )
AlibabaTrojan:Win32/Coinminer.2cc
K7GWAdware ( 0055be151 )
Cybereasonmalicious.8f35d5
CyrenTrojan.AIIF-3
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.QB potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Coinminer.XMRig-9775031-0
Kasperskynot-a-virus:RiskTool.BAT.BitCoinMiner.ab
BitDefenderTrojan.Sesfix.3
NANO-AntivirusRiskware.Win64.BitMiner.idpmjz
AvastBV:Miner-HA [PUP]
SophosGeneric Reputation PUA (PUA)
DrWebTool.BtcMine.2562
VIPRETrojan.Win32.Generic!BT
TrendMicroCoinminer.BAT.MALXMR.COMP
EmsisoftTrojan.Sesfix.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Miner.nlk
AviraPUA/CoinMiner.CT
MAXmalware (ai score=79)
Antiy-AVLRiskWare[RiskTool]/Win32.BitMiner
KingsoftWin32.Troj.Generic.a.(kcloud)
GridinsoftRansom.Win32.Gen.sa
GDataWin32.Malware.Coinminer.0DKRM2
AhnLab-V3Malware/Win32.Generic.C4198781
ALYacGen:Variant.Application.Miner.2
MalwarebytesMalware.AI.3687254859
TrendMicro-HouseCallCoinminer.BAT.MALXMR.COMP
RisingHackTool.XMRMiner!1.C2EC (CLASSIC)
FortinetW32/BtcMineNET.2!tr
AVGBV:Miner-HA [PUP]
PandaTrj/CI.A

How to remove Script.Trojan.38726?

Script.Trojan.38726 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment