Trojan

Trojan.Script.PWRS removal instruction

Malware Removal

The Trojan.Script.PWRS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Script.PWRS virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Script.PWRS?


File Info:

name: EF36296C35CAD12DD277.mlw
path: /opt/CAPEv2/storage/binaries/4d2a7bc887914aa382c7c989a814ea137f061c8b5aa2a5c3822613b8857bc00c
crc32: 435EA8DE
md5: ef36296c35cad12dd277fafdbd791917
sha1: 5bc65a0d2a9cb4710707db578a5682166b2ffa48
sha256: 4d2a7bc887914aa382c7c989a814ea137f061c8b5aa2a5c3822613b8857bc00c
sha512: 8f32420fc7e7dd453d25fd86aa40ff83dacb334267e2b752f661cbb4c216f8d281f824399511b15d252643f1f6b8c9b4c473238e8419347c89469389aa108e18
ssdeep: 24576:SFGpY1YzlMLvfarU5XCg3aQAEofVwmH2pJnKl3juQ55313d:SF7BSNbW/Kl3F
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DAA5F903AA8B0E75DDD237B461CB533AA734FE30CA2A9B7FB609C53559532C46C1A742
sha3_384: a5248885abe84d68221ef09323eb44e461e08d0fc127e5bfdbcb5310042e1217b161019d6f3aee9b2b91e2963b8233d5
ep_bytes: 83ec0cc705b8434e0000000000e8deae
timestamp: 2022-04-26 06:15:21

Version Info:

0: [No Data]

Trojan.Script.PWRS also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.86998
FireEyeTrojan.GenericKDZ.86998
McAfeeGenericRXSS-GF!EF36296C35CA
CylanceUnsafe
K7AntiVirusTrojan ( 0058270d1 )
K7GWTrojan ( 0058270d1 )
SymantecML.Attribute.HighConfidence
ClamAVWin.Malware.Generickdz-9888427-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.86998
AvastWin32:CrypterX-gen [Trj]
TencentTrojan.Win32.Zapchast.xa
Ad-AwareTrojan.GenericKDZ.86998
EmsisoftTrojan.GenericKDZ.86998 (B)
McAfee-GW-EditionArtemis
SophosMal/Generic-S
GDataWin32.Trojan.PSE.W32D6U
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D153D6
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Muldrop.R488400
Acronissuspicious
ALYacTrojan.GenericKDZ.86998
MalwarebytesTrojan.Script.PWRS
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FJWN!tr
AVGWin32:CrypterX-gen [Trj]

How to remove Trojan.Script.PWRS?

Trojan.Script.PWRS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment