Trojan

Trojan.Script.474477 removal

Malware Removal

The Trojan.Script.474477 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Script.474477 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Script.474477?


File Info:

name: E47BBE4C9D9B05548605.mlw
path: /opt/CAPEv2/storage/binaries/872db225ccd1d70cd90391f078c6963cd2ecab4c054e31633448f62846bccc93
crc32: 8D72B26D
md5: e47bbe4c9d9b05548605c88302fcad8d
sha1: 63fec05691397d44e1d8ff028a2407c96e1e45f6
sha256: 872db225ccd1d70cd90391f078c6963cd2ecab4c054e31633448f62846bccc93
sha512: 831a4314c949265a9aef3c42a2e22b8a755de062dd2d6c7d795c1b33aba0a6e4778f44934fef2365a24a4e3b32635c3895268ba36a5002587cab0701bcc4fbd8
ssdeep: 12288:zaWzgMg7v3qnCiMErQohh0F4CCJ8lnyi8X:2aHMv6Corjqnyi8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4D4AE12F7D680B6D99338B5297BE32BEB3576194327C497ABE02E738F111405B3A361
sha3_384: f71695738c50608efce0d9e4c50969a3554b94f9e9a7c4a3e24c032e6c3d59a40dce5773761afdfae5d91b0dc5cc1248
ep_bytes: e8a7c00000e979feffffcccccccccccc
timestamp: 2010-04-16 07:47:33

Version Info:

FileVersion: 1.0.0.2
FileDescription: oem
LegalCopyright: oem
Translation: 0x0804 0x04b0

Trojan.Script.474477 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanTrojan.Script.474477
FireEyeGeneric.mg.e47bbe4c9d9b0554
ALYacTrojan.Script.474477
CylanceUnsafe
ZillyaTrojan.Agent.Win32.685998
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanClicker:Win32/StartPage.fc15a7de
K7GWTrojan ( 0055e40d1 )
K7AntiVirusTrojan ( 0055e40d1 )
BaiduWin32.Trojan.StartPage.ed
SymantecTrojan.Gen
ESET-NOD32Win32/StartPage.OBL
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Clicker.Win32.Agent.rux
BitDefenderTrojan.Script.474477
NANO-AntivirusTrojan.Script.Agent.emwasc
AvastWin32:Malware-gen
TencentWin32.Trojan.Agent.Ajlj
Ad-AwareTrojan.Script.474477
EmsisoftTrojan.Script.474477 (B)
DrWebTrojan.Click2.34119
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionBehavesLike.Win32.Virus.jh
SophosMal/Generic-S
IkarusTrojan.Script
GDataTrojan.Script.474477 (2x)
WebrootW32.Malware.Heur
AviraHEUR/AGEN.1229538
ArcabitTrojan.Script.D73D6D
ZoneAlarmUDS:Trojan-Clicker.Win32.Agent.rux
MicrosoftTrojan:Win32/Occamy.C87
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Sohanad.C284086
McAfeeArtemis!E47BBE4C9D9B
MAXmalware (ai score=100)
VBA32TrojanClicker.Agent
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
MaxSecureVirus.W32.Pioneer.H
FortinetW32/Agent.obl!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Script.474477?

Trojan.Script.474477 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment