Trojan

Trojan.Prepscram information

Malware Removal

The Trojan.Prepscram is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Prepscram virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Prepscram?


File Info:

name: 28FD4F8C5A75BB716F8F.mlw
path: /opt/CAPEv2/storage/binaries/1b23c8054f65ae3c9e6d956ea8c091779d3fe0988fddf2ce5e38929420d1f9ae
crc32: 6A941ECE
md5: 28fd4f8c5a75bb716f8fa26c114c0167
sha1: 1749814f213cd37241998c309b215a8b11084dbd
sha256: 1b23c8054f65ae3c9e6d956ea8c091779d3fe0988fddf2ce5e38929420d1f9ae
sha512: 0c848060f56383e5009c17241934f7ecc1f95dab77fc529e2e8dc47b544e2d18ea23cefb8ac05e8d615ee3c448dd04e54e4b7617ab08cb8f7e2df6a129fa1190
ssdeep: 768:XIX3LK0QprNKmcNWEcX0ksWjcdMHxr6e183oxBrUxMMfe/hW7r+1RGn8NIo:OK0KrcNTcXPsWjcd+xhryMGUGn82
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5936C11B6D58432E472493A48E4812146BEBDF29EB58D87B3D8214F4AF21D68F39F73
sha3_384: cf79624831f4abc0d0b2bb924e9e9bd6080089ce51fdcb2d6071f327e04d0ae6d72a7b48533f0130980e212c52d89dcd
ep_bytes: 086a0de88615000059c38b75086a0ce8
timestamp: 2015-05-05 13:45:31

Version Info:

0: [No Data]

Trojan.Prepscram also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKDZ.70388
ClamAVWin.Malware.Zusy-9957983-0
CAT-QuickHealTrojan.Prepscram
ALYacTrojan.GenericKDZ.70388
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Prepscram.679ae810
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.c5a75b
CyrenW32/Agent.FWC.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKDZ.70388
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:DropperX-gen [Drp]
EmsisoftTrojan.GenericKDZ.70388 (B)
DrWebTrojan.DownLoader23.51365
VIPRETrojan.GenericKDZ.70388
TrendMicroTROJ_GEN.R002C0DGT23
McAfee-GW-EditionBehavesLike.Win32.Generic.nt
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.28fd4f8c5a75bb71
SophosMal/EncPk-F
IkarusVirus.Win32.Agent
GDataWin32.Trojan.Agent.AXD
Antiy-AVLTrojan/Win32.Razy
ArcabitTrojan.Generic.D112F4
ViRobotTrojan.Win.Z.Agent.94208.NK
MicrosoftTrojan:Win32/Prepscram.A!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R584903
McAfeeGenericRXVS-GX!28FD4F8C5A75
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGT23
RisingVirus.CTS!1.DA0D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Razy.EA15!tr
BitDefenderThetaAI:Packer.BE77A4221E
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Prepscram?

Trojan.Prepscram removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment