Trojan

Should I remove “Trojan.ScriptKD.7560”?

Malware Removal

The Trojan.ScriptKD.7560 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ScriptKD.7560 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Collects information about installed applications
  • Accessed credential storage registry keys

How to determine Trojan.ScriptKD.7560?


File Info:

name: 429DA1366E89858A0C5F.mlw
path: /opt/CAPEv2/storage/binaries/b204c6d82dbc6aec99fa0ecec68331180ed8ade6abc695fb0f919815a4252e8a
crc32: 859AEFB3
md5: 429da1366e89858a0c5f88bae329654c
sha1: 06bcd8173860593489e4b99fa78b67f03f438b88
sha256: b204c6d82dbc6aec99fa0ecec68331180ed8ade6abc695fb0f919815a4252e8a
sha512: 7054fc7a48929b06dae8c7a574d446c106832823fff1e34019ba1b5040934b1234bb6b7e0c3f77e6922bec52a3ea3d9593774ae42fcb5502d9af51d539eca7cc
ssdeep: 98304:4PLcD3mNzGaZCbkkCHylTNa9+oNfONeMBODdNBcrVm2IS:8cEGaZCbBC8TQrNmcMBFro2IS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12216332267E68036D01778B4D4BC97617F3679E25236589BEBD0013C6B22EF5C77029B
sha3_384: e67b9f5bf0446045b4127dbba3f9d763ddc19d100f0462bf9a17c44d8344280d26dc77acdc25a56883c35a53f2086f30
ep_bytes: e8f0570000e978feffff8bff558bec56
timestamp: 2013-08-06 15:29:13

Version Info:

0: [No Data]

Trojan.ScriptKD.7560 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.ScriptKD.7560
FireEyeTrojan.ScriptKD.7560
CylanceUnsafe
SangforTrojan.Win32.Generic.8
CrowdStrikewin/malicious_confidence_60% (W)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ESET-NOD32a variant of Win32/Injector.BCBB
APEXMalicious
ClamAVWin.Trojan.Inject-14546
KasperskyUDS:Trojan.Win32.Inject.mnvr
BitDefenderTrojan.ScriptKD.7560
NANO-AntivirusTrojan.Win32.Inject.dkkkgv
AvastWin32:InstallMonstr-EG [PUP]
Ad-AwareTrojan.ScriptKD.7560
SophosMal/Generic-S + Install Monster (PUA)
ComodoTrojWare.Win32.Injector.BCBA@59pyfy
DrWebTrojan.InstallMonster.120
ZillyaDropper.Dapato.Win32.20900
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftTrojan.ScriptKD.7560 (B)
IkarusTrojan.Injector
GDataGen:Variant.Graftor.140295
JiangminTrojan/Inject.awic
AviraHEUR/AGEN.1224521
KingsoftWin32.Troj.Inject.mn.(kcloud)
ArcabitTrojan.ScriptKD.D1D88
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!429DA1366E89
MAXmalware (ai score=86)
VBA32Trojan.Inject
TrendMicro-HouseCallTROJ_GEN.R03BH0CFI22
RisingTrojan.Inject!8.103 (CLOUD)
FortinetW32/Injector.BCBB!tr
AVGWin32:InstallMonstr-EG [PUP]
Cybereasonmalicious.66e898
PandaTrj/CI.A

How to remove Trojan.ScriptKD.7560?

Trojan.ScriptKD.7560 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment