Trojan

Should I remove “Trojan.ScriptKD.3769”?

Malware Removal

The Trojan.ScriptKD.3769 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ScriptKD.3769 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
fredchen.gotdns.ch

How to determine Trojan.ScriptKD.3769?


File Info:

crc32: 0FBAF7D3
md5: 6abb5ce814ff591032863b4359b64f58
name: 6ABB5CE814FF591032863B4359B64F58.mlw
sha1: b45826c25ea1c42f651c9ab90930a541a7c7761c
sha256: 66115617b7b4fe181ab03f86b84a2141267f4e646a005eb0ae4195645bab7ce3
sha512: 95c17f3d3879d18856c5bb8dd419782824182d37d45c3cb8aadad510e53c2090f236528877a83f29dedd5672868494de7529d9dd0c9da66b4b1c3f1744428ba2
ssdeep: 49152:j0AgSSEBfKSzb08+PUD5lCCWaAAuc8+OdHLJEU49HB4DK+7U:AuSED0GDC5aZXVKJEU41CrQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: WAVN5BXW
InternalName: regrreg.exe
FileVersion: 37.3.35.3277
CompanyName:
trademark: WAVN5BXW
ProductName: WS7ZEN40
ProductVersion: 1.0.0.0
FileDescription: 4P7TL2VE
OriginalFilename: regrreg.exe
Translation: 0x0000 0x04b0

Trojan.ScriptKD.3769 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.ScriptKD.3769
FireEyeGeneric.mg.6abb5ce814ff5910
ALYacTrojan.ScriptKD.3769
BitDefenderTrojan.ScriptKD.3769
BitDefenderThetaGen:NN.ZemsilF.34590.An0@aGO0Zdl
SymantecTrojan.Gen.2
APEXMalicious
KasperskyTrojan.Win32.Agent.gen
Ad-AwareTrojan.ScriptKD.3769
F-SecureTrojan.TR/Patched.Gen
DrWebTrojan.Siggen11.188
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.vc
EmsisoftTrojan.ScriptKD.3769 (B)
IkarusTrojan.ScriptKD
AviraTR/Patched.Gen
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.ScriptKD.DEB7
ZoneAlarmTrojan.Win32.Agent.gen
GDataVBS.Heur.Laburrak.11.B3B10C26.Gen
CynetMalicious (score: 85)
McAfeeArtemis!6ABB5CE814FF
AVGFileRepMalware
Cybereasonmalicious.814ff5

How to remove Trojan.ScriptKD.3769?

Trojan.ScriptKD.3769 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment