Trojan

Trojan.Script.476123 malicious file

Malware Removal

The Trojan.Script.476123 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Script.476123 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Script.476123?


File Info:

name: 4DD7720829CCC7FA347D.mlw
path: /opt/CAPEv2/storage/binaries/86552e1af956a5d32ef3189caed8f5c4d6a07665de0332e5826f527d1b61f85d
crc32: 5429B939
md5: 4dd7720829ccc7fa347dd3151865b35e
sha1: 232345916a11505cf811c875a00a435bcd90116e
sha256: 86552e1af956a5d32ef3189caed8f5c4d6a07665de0332e5826f527d1b61f85d
sha512: b07cc555a6814be0ebb768d873f4ec2e52067970d11c42f1436323501d203ca9ba5d1f9317add1363338a74c5ab5cb0e580704b9082982f99e1126e76680dcc5
ssdeep: 3072:f3qJ3dPrq8iYloAAsJP8OJkZc1mEbY+PR3Pmhh9dINqH:f3u3dPrriYlDAsJPtJgc1mEbDmhF9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BB3BF1BF7E490F7D881513009FE2368F6F4E92892B98507FF920F0ABF34696521B942
sha3_384: 7e5f0a234548327355e1916a65c40cff55a15c40f0bd712deb450bedbbcc2730fbca8d95ffb727f0b191797014e888e0
ep_bytes: e81effffff33c050505050e8bf2a0000
timestamp: 2010-03-15 06:27:58

Version Info:

0: [No Data]

Trojan.Script.476123 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.Script.476123
ALYacTrojan.Script.243874
CylanceUnsafe
VIPRETrojan.Script.476123
Cybereasonmalicious.829ccc
SymantecTrojan.Gen.MBT
ESET-NOD32VBS/Packed.Runner.D potentially unwanted
APEXMalicious
ClamAVWin.Trojan.StartPage-43
KasperskyTrojan.VBS.Agent.kq
BitDefenderTrojan.Script.476123
NANO-AntivirusTrojan.Script.Agent.buyqk
AvastVBS:Agent-CA [Trj]
ComodoMalware@#3izvfawsw9hif
DrWebTrojan.MulDrop21.15319
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.4dd7720829ccc7fa
EmsisoftTrojan.Script.476123 (B)
GDataTrojan.Script.243874
GoogleDetected
AviraHTML/Infected.WebPage.Gen2
MAXmalware (ai score=89)
ArcabitTrojan.Script.D743DB [many]
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!4DD7720829CC
VBA32VBS.Disabler.NAA
RisingTrojan.Agent!8.B1E (TOPIS:E0:XtTRod13aQU)
YandexVBS.Psyme.GL
IkarusTrojan.Script
FortinetVBS/Dloader.LNK!tr
AVGVBS:Agent-CA [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.Script.476123?

Trojan.Script.476123 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment