Trojan

Trojan.Script.Obf removal tips

Malware Removal

The Trojan.Script.Obf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Script.Obf virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the KeyBase malware family
  • Deletes executed files from disk
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Script.Obf?


File Info:

name: 1D78D8381415D7F07DA6.mlw
path: /opt/CAPEv2/storage/binaries/e928322d08b97442dcdb4d683bde6702fe9d499ed765ee1c3077b0d09603e038
crc32: 0E0E842F
md5: 1d78d8381415d7f07da6fd568f577fd2
sha1: 13974fd4ad9d6ac87dc8280e37b1bbca2b1ad52a
sha256: e928322d08b97442dcdb4d683bde6702fe9d499ed765ee1c3077b0d09603e038
sha512: 6c98d44f4f500b2f7e55b51209943ae113b1dbad91e8794ee00cc7fd56e64729db4f4ba40b81444b61d9ee37bbf8164f254c5a3345c6599066f9a468b2cd98d6
ssdeep: 24576:jbCj2sObHtqQ4QIYmdEo4MvlHYkU+xma5V7Dgwr/pSiSnYIH7BM7WX:jbCjPKNqQIFIbBMyX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EA5D0C6F2EA40E6DC023FF5582467C79B344736473840597BAB3D498F234A9C16ABB6
sha3_384: 82ea7e376fdf4a52a1c088f452349a9d34e956f7b4a72b9db463599280b986f301035b5cf517d12270beabe853aaab65
ep_bytes: e837c20000e979feffffcccccccccccc
timestamp: 2010-01-15 16:09:54

Version Info:

CompanyName: CHENGDU YIWO Tech Development Co., Ltd
FileDescription: EaseUS Data Recovery Wizard
FileVersion: 9.0.0
InternalName: Data Recovery Wizard
LegalCopyright: Copyright (c) 2004-2015 EaseUS.ALL RIGHTS RESERVED.
OriginalFilename: EaseUS Data Recovery Wizard
ProductName: EaseUS Data Recovery Wizard
ProductVersion: 9.0.0
Translation: 0x0804 0x04b0

Trojan.Script.Obf also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Siggen17.52162
MicroWorld-eScanTrojan.Agent.BNAA
FireEyeGeneric.mg.1d78d8381415d7f0
McAfeeGenericRXAA-FA!1D78D8381415
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d533f1 )
AlibabaTrojan:Script/Inject.91c2b696
K7GWTrojan ( 004d533f1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/AutoIt.WB.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.AutoIt.FR
APEXMalicious
ClamAVWin.Malware.Bnaa-9957967-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.Agent.BNAA
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Autoit.xc
EmsisoftTrojan.Agent.BNAA (B)
F-SecureHeuristic.HEUR/AGEN.1321349
VIPRETrojan.Agent.BNAA
TrendMicroTSPY_ATBOT.SMAR5
McAfee-GW-EditionBehavesLike.Win32.Generic.vm
SophosTroj/Inject-HWO
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Agent.BNAA
JiangminTrojanDownloader.Umbra.n
GoogleDetected
AviraHEUR/AGEN.1321349
Antiy-AVLTrojan/Autoit.Winmgr.a
ArcabitTrojan.Agent.BNAA
ViRobotTrojan.Win.Z.Autoit.2198586.E
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C2533422
VBA32Trojan.Script.Obf
ALYacTrojan.Agent.BNAA
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ATBOT.SMAR5
RisingTrojan.Obfus/Autoit!1.E083 (CLASSIC)
IkarusTrojan.Win32.Autoit
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Trojan_AutoIt.BO!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Script.Obf?

Trojan.Script.Obf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment