Trojan

Trojan.ScriptKD.1420 removal instruction

Malware Removal

The Trojan.ScriptKD.1420 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ScriptKD.1420 virus can do?

  • Injection (inter-process)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detected Armadillo packer using a known mutex
  • Detected Armadillo packer using a known registry key
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.ScriptKD.1420?


File Info:

crc32: 45D3CA6C
md5: 7548ac94ce78b372134e1c2ef1e6fc9b
name: 7548AC94CE78B372134E1C2EF1E6FC9B.mlw
sha1: 903f89949a8c53446b1ea9bfd66649c3382a98b1
sha256: 5ed8beb05c838c2878c7c3e08a0d4398767fec53a8f9197db4814327b8072800
sha512: 6cfbe54109389c6adb2f59a6d5ddeda1b98ed533a27c625113c9b873d4a9f5664e118a5c78288934f85554d666c119f49d16245e838ad9c435db9e07bd3de3b1
ssdeep: 49152:ijcNJ0P94ctvAr67LBMzvFDUNjMzJ3I93wqOG5Dz00p8zQbgYOW3Er:Ic4PKcJvCYNMV3Ia3Yw0XUpWI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.ScriptKD.1420 also known as:

K7AntiVirusTrojan ( 700000121 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.Starter.3011
ALYacGen:Variant.MSILPerseus.3835
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.15895
SangforRansom.Win32.Blocker.8
AlibabaBackdoor:MSIL/DarkKomet.eeef16b9
K7GWTrojan ( 700000121 )
Cybereasonmalicious.4ce78b
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.AXL
APEXMalicious
AvastWin32:Dropper-gen [Drp]
CynetMalicious (score: 99)
KasperskyHEUR:Backdoor.MSIL.DarkKomet.gen
BitDefenderTrojan.ScriptKD.1420
NANO-AntivirusTrojan.Win32.Blocker.cvpjdy
MicroWorld-eScanTrojan.ScriptKD.1420
TencentWin32.Trojan.Blocker.Agbg
Ad-AwareTrojan.ScriptKD.1420
SophosMal/Generic-S
ComodoMalware@#2ko4e4xg712og
BitDefenderThetaGen:NN.ZemsilF.34236.gm0@aezN8moi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.7548ac94ce78b372
EmsisoftTrojan.ScriptKD.1420 (B)
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1105138
Antiy-AVLTrojan/Generic.ASMalwS.923A4C
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.C5E
ArcabitTrojan.ScriptKD.D58C
GDataGen:Variant.MSILPerseus.3835
McAfeeArtemis!7548AC94CE78
MAXmalware (ai score=100)
PandaTrj/CI.A
YandexTrojan.Blocker!x2WEHqeGZvE
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Generic.AP.B94DF8!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml

How to remove Trojan.ScriptKD.1420?

Trojan.ScriptKD.1420 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment