Trojan

Trojan.ScriptKD.403 removal

Malware Removal

The Trojan.ScriptKD.403 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ScriptKD.403 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.ScriptKD.403?


File Info:

name: 40EBA1DF6A03A29A327D.mlw
path: /opt/CAPEv2/storage/binaries/93aa6e3d19543d155fd825696c96e1e8240993cb083137fe011156c42198c5a1
crc32: CAAC6B7B
md5: 40eba1df6a03a29a327d2ccd08a2805b
sha1: 28c7d4928b89414bf573822cdf072b395bda5ce0
sha256: 93aa6e3d19543d155fd825696c96e1e8240993cb083137fe011156c42198c5a1
sha512: e4297a5a1b20b3eb1239b18063e62496078c5dc4fcd130ecc89cf145598f9107a92726eb9d3175ffaf9f2932e7e88a9f97e86d8c7d4e06d9427323d40665b8d8
ssdeep: 12288:Y3nZMhJ+ubNJJ/6PiF/2YAtZU0+5Kl4Qau4pD+dE35dzep2C5HlixFAddi/Byhwp:Y3nZqfbvJ/CEorUkWQv4l/dzeYCxgJ4m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8E4121233D745B5E5A256319E752B4AC279BE30F934E08DDB920B4D3B70B42CA1AF93
sha3_384: af70284e967a9ceff3432fb38c2376ed41d2d72c3aec8f1c463443a180af45130b0ef4efd4db2246830fd02c529c8628
ep_bytes: e8e3feffff33c050505050e8f22d0000
timestamp: 2012-02-17 14:55:21

Version Info:

0: [No Data]

Trojan.ScriptKD.403 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
DrWebTrojan.PWS.Banker1.11693
MicroWorld-eScanTrojan.ScriptKD.403
FireEyeTrojan.ScriptKD.403
CAT-QuickHealTrojanSpy.Banker
ALYacGen:Variant.Fragtor.280738
Cylanceunsafe
SangforBanker.Win32.Agent.Vlrk
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanBanker:Win32/Banker.ce507d7d
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.f6a03a
BitDefenderThetaGen:NN.ZelphiF.36350.kmGdauZD0rob
CyrenW32/OnlineGames!Generic
SymantecInfostealer.Bancos
ESET-NOD32a variant of Win32/Spy.Banker.ZUU
APEXMalicious
ClamAVWin.Packed.Scriptkd-9841554-0
KasperskyTrojan-Banker.Win32.Banker.bphd
BitDefenderTrojan.ScriptKD.403
NANO-AntivirusTrojan.Win32.Banker.cqtplg
AvastWin32:Malware-gen
TencentWin32.Trojan-Banker.Banker.Dkjl
EmsisoftTrojan.ScriptKD.403 (B)
F-SecureTrojan.TR/Spy.Banker.kjwmt
VIPRETrojan.ScriptKD.403
TrendMicroTROJ_GEN.R002C0DEA23
McAfee-GW-EditionBehavesLike.Win32.Dropper.jc
Trapminesuspicious.low.ml.score
SophosMal/Packer
IkarusTrojan-Proxy
GDataTrojan.ScriptKD.403
WebrootW32.Trojan.ScriptKD
GoogleDetected
AviraTR/Spy.Banker.kjwmt
Antiy-AVLTrojan[Banker]/Win32.Banker
XcitiumPacked.Win32.MNSP.Gen@2697wr
ArcabitTrojan.ScriptKD.403 [many]
ZoneAlarmTrojan-Banker.Win32.Banker.bphd
MicrosoftTrojanSpy:Win32/Banker
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Banker.C5474293
McAfeeArtemis!40EBA1DF6A03
MAXmalware (ai score=81)
VBA32TrojanBanker.Banker
MalwarebytesTrojan.MalPack.NSPack
PandaTrj/CI.A
ZonerProbably Heur.ExeHeaderP
RisingTrojan.Generic@AI.95 (RDML:nbt5y3KfsDKNPUoaUglc9w)
SentinelOneStatic AI – Malicious SFX
FortinetW32/Banker.YUU!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.ScriptKD.403?

Trojan.ScriptKD.403 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment