Trojan

Trojan.ScriptKD.7957 malicious file

Malware Removal

The Trojan.ScriptKD.7957 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ScriptKD.7957 virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Trojan.ScriptKD.7957?


File Info:

crc32: ACA062BB
md5: d69d058dbdc4cd04c2b035a834a7e0ac
name: D69D058DBDC4CD04C2B035A834A7E0AC.mlw
sha1: 7c41ab0a605998c403a86f815ecc55bd2eb7f2a7
sha256: 9aa76905828cbcf33b50907d71eab8ef0e4b5d75271d9b352daab802d92c307b
sha512: 0522fa7d44875e7209f3f66872f759641e35c93375331483e68a9e1203be76e0e76921c94e878bdb8b01dafe0e85ec9fda73a900ce6609b048cc007cb26699f9
ssdeep: 98304:/CB7F9nspRo0P47hDQFwj1eukzAiz+1C+zdkZNVct:/CxnsRoIOuFy14rz0zdk1O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.ScriptKD.7957 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055b4a31 )
Elasticmalicious (high confidence)
DrWebTool.BtcMine.2110
CynetMalicious (score: 100)
ALYacTrojan.VBS.Agent.AUA
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0055b4a31 )
Cybereasonmalicious.dbdc4c
CyrenW64/Application.MTOT-7067
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Tool.Kmsauto-6988298-0
KasperskyHEUR:Trojan.Win32.Miner.gen
BitDefenderTrojan.ScriptKD.7957
NANO-AntivirusTrojan.Win64.Miner.gfqtuh
MicroWorld-eScanTrojan.ScriptKD.7957
SophosGeneric ML PUA (PUA)
ComodoApplicUnwnt@#11s2kzphr811g
VIPRETrojan.Win32.Generic!BT
TrendMicroCoinminer.Win64.MALXMR.SMFCD01
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.d69d058dbdc4cd04
EmsisoftTrojan.ScriptKD.7957 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Script.ahic
AviraHEUR/AGEN.1119227
eGambitUnsafe.AI_Score_71%
Antiy-AVLTrojan/Generic.ASMalwS.2CD7B6D
MicrosoftTrojan:Win64/DisguisedXMRigMiner
ArcabitTrojan.ScriptKD.D1F15
ZoneAlarmHEUR:Trojan-Dropper.Win32.Miner.gen
GDataWin32.Riskware.HackKMS.G
AhnLab-V3HackTool/Win.KMSAuto.R430157
McAfeeArtemis!D69D058DBDC4
MAXmalware (ai score=87)
VBA32Trojan.Miner
MalwarebytesTrojan.BitCoinMiner
PandaVBS/Agent.KOQ
RisingHackTool.XMRMiner!1.C2EC (CLASSIC)
YandexTrojan.GenAsa!rsYRhdTgOyw
IkarusHackTool.Win32.Gendows
FortinetW64/CryptoMiner.L!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.ScriptKD.7957?

Trojan.ScriptKD.7957 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment