Trojan

Trojan.ScriptKD.1797 removal tips

Malware Removal

The Trojan.ScriptKD.1797 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ScriptKD.1797 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • The sample wrote data to the system hosts file.

How to determine Trojan.ScriptKD.1797?


File Info:

name: 47DB7665EE819D26850C.mlw
path: /opt/CAPEv2/storage/binaries/afe2dcbd7881cf92ba97443f57e410ffa35c246a97a3f0edcf10b7627103dbc6
crc32: 908F1083
md5: 47db7665ee819d26850cbc1392dce5fe
sha1: 719e0d4e4b1f784c25225ae932125be8eba698c8
sha256: afe2dcbd7881cf92ba97443f57e410ffa35c246a97a3f0edcf10b7627103dbc6
sha512: 8b8e45e5810632859f6e5ba3a2c3bd6cf8fa465d7df392af358e128184552a763df76aff589dc94b7d8c1f8b44d68a7a6c42a4b91fd7703d717553a665d894fa
ssdeep: 24576:6mOMSPEfxYIbhGXFL5Ibxo+Nkyp9RyjfjoEZaUGBErLipVQQpipMjaraoIZeYD89:cPehG1a1p9A7jtZaUGB/j3QPWjW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D685232136D08171F4B769308C7AA772ED75BD391974C68E63861F2D2EB0B91CB12B63
sha3_384: 6376519d29607e04792a8c3403652289e8523dbab50592f495307a6c222ab4344c1200e743f35f8d777e2e9850c897a3
ep_bytes: e85d640000e978feffff8bff558bec56
timestamp: 2014-06-10 17:11:07

Version Info:

0: [No Data]

Trojan.ScriptKD.1797 also known as:

LionicRiskware.Win32.Qhost.1!c
MicroWorld-eScanTrojan.ScriptKD.1797
FireEyeTrojan.ScriptKD.1797
McAfeeArtemis!47DB7665EE81
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.ScriptKD.1797
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5ee819
SymantecPUA.Gen.2
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:RiskTool.Win32.Qhost.sy
AlibabaRiskWare:Win32/Qhost.5af40bbb
McAfee-GW-EditionBehavesLike.Win32.Coinminer.tc
EmsisoftTrojan.ScriptKD.1797 (B)
IkarusTrojan.ScriptKD
MAXmalware (ai score=82)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.ScriptKD.1797
ALYacTrojan.ScriptKD.1797
TencentWin32.Risk.Qhost.Pfjv
FortinetMalicious_Behavior.SB
AVGFileRepMalware
AvastFileRepMalware

How to remove Trojan.ScriptKD.1797?

Trojan.ScriptKD.1797 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment