Trojan

How to remove “Trojan.Separ”?

Malware Removal

The Trojan.Separ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Separ virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Separ?


File Info:

name: 6E1A4491A3C6C7A235D9.mlw
path: /opt/CAPEv2/storage/binaries/a813f3f56e92f284b58e05233f8b2ed408f3a1c496606d44283304ff657790ca
crc32: 50F20191
md5: 6e1a4491a3c6c7a235d99440db386f15
sha1: 3d77fe200de5b95b1b733ef55b29bbcd372248c5
sha256: a813f3f56e92f284b58e05233f8b2ed408f3a1c496606d44283304ff657790ca
sha512: 225936beb302311091e39acb797c225bc41e289259db7358fd3dd92961b338877739edccb1c1bfdfb0805ee90a86281bf1d9f58e93bf0b452b5d0710596b8741
ssdeep: 24576:ObCj2sObHtqQ4QEfCr7w7yvuqqNq8FroaSaPXRackmrM4Biq7MhLv9GImmVfq4em:ObCjPKNqQEfsw43qtmVfq49
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114C5D0C5F2AA40E2DC123FF5582567C78B344E364B3840597BAB3D498F335E6C11AAB6
sha3_384: 2ee83e64dfb285a15c768c078ba81adb77e70aa3379149fa10a2d2a6256c5330ee9b9a611b957cd2b68342ccf61f672b
ep_bytes: e837c20000e979feffffcccccccccccc
timestamp: 2010-01-15 16:09:54

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Neil Hodgson neilh@scintilla.org
FileDescription: SciTE - a Scintilla based Text Editor
FileVersion: 1.75
InternalName: SciTE
LegalCopyright: Copyright 1998-2007 by Neil Hodgson
OriginalFilename: SciTE.EXE
ProductName: SciTE
ProductVersion: 1.75

Trojan.Separ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.168457
FireEyeGeneric.mg.6e1a4491a3c6c7a2
CAT-QuickHealTrojan.Separ
SkyhighBehavesLike.Win32.TrojanAutoIt.vm
ALYacGen:Variant.Jaik.168457
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Jaik.168457
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005936091 )
BitDefenderGen:Variant.Jaik.168457
K7GWTrojan ( 005936091 )
Cybereasonmalicious.00de5b
VirITTrojan.Win32.AutoIt.GD
SymantecBloodhound.Malautoit
ESET-NOD32MSIL/Spy.Agent.AGJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Autoit-6996111-0
KasperskyUDS:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Mlw.kcxttm
RisingTrojan.Obfus/Autoit!1.E083 (CLASSIC)
SophosTroj/Atbot-B
F-SecureTrojan.TR/Agent.odipt
DrWebTrojan.Siggen17.49996
TrendMicroTSPY_ATBOT.SMAR5
EmsisoftGen:Variant.Jaik.168457 (B)
IkarusTrojan.MSIL.Spy
GDataWin32.Trojan.PSE.10T5SOT
JiangminTrojan.Script.afmg
WebrootW32.Trojan.Gen
VaristW32/Autoit.JFHF-9022
AviraTR/Agent.odipt
Antiy-AVLTrojan/Autoit.Winmgr.a
Kingsoftmalware.kb.a.973
ArcabitTrojan.Jaik.D29209
ZoneAlarmUDS:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Separ.GMD!MTB
GoogleDetected
AhnLab-V3Spyware/Win.Atbot.R531437
McAfeeGenericRXAA-FA!6E1A4491A3C6
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
VBA32Trojan.Autoit.Obfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ATBOT.SMAR5
TencentTrojan.Win32.Sabsik.haq
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetAutoIt/Agent.AGJ!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Separ?

Trojan.Separ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment