Trojan

Trojan:HTML/Scrinject.C!bit (file analysis)

Malware Removal

The Trojan:HTML/Scrinject.C!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:HTML/Scrinject.C!bit virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (11 unique times)
  • Performs some HTTP requests
  • Generates some ICMP traffic

Related domains:

www.bing.com
www.blogger.com
ocsp.pki.goog
fonts.googleapis.com
ajax.googleapis.com
fonts.gstatic.com
html5shiv.googlecode.com
blogtipsntricks.googlecode.com
ie7-js.googlecode.com
2.bp.blogspot.com
3.bp.blogspot.com
resources.blogblog.com
4.bp.blogspot.com
yourjavascript.com

How to determine Trojan:HTML/Scrinject.C!bit?


File Info:

crc32: 1C6ED267
md5: 0d3174a965a6200fbb87e596308a8b64
name: upload_file
sha1: 2a2b226244d2b76a6c961debf91fe7ef67098df9
sha256: ed224cad58fa79a15d2989bfde3c25f8b1d271a51dec9e6fd0310f452f9df895
sha512: fe479ab6001809cd5237e2ae9d590ae71892ed0e458b51f64b3eab84b0e44417700eeac262ad103c5836fbb52b5c24ccb79f959b6f3dd3e230d9627c49e27ff4
ssdeep: 1536:hfyyL5SUlvN/whenL6JuCw46TrRf06c99R7IGrNBs5IyCYHvn71uiosy2Xs0uCWN:hfyqYgtD0st81vlrtMCS9D8
type: HTML document, ASCII text, with very long lines

Version Info:

0: [No Data]

Trojan:HTML/Scrinject.C!bit also known as:

MicroWorld-eScanJS:Trojan.JS.Agent.RQO
CAT-QuickHealHtml.Trojan.A906980
AegisLabTrojan.HTML.Generic.4!c
SangforMalware
ArcabitJS:Trojan.JS.Agent.RQO
BaiduJS.Trojan.Kryptik.s
CyrenJS/Crypted.RI
SymantecHeur.AdvML.JS.C
AvastJS:Decode-BTB [Trj]
BitDefenderJS:Trojan.JS.Agent.RQO
NANO-AntivirusTrojan.Script.Kryptik.ewlsdt
Ad-AwareJS:Trojan.JS.Agent.RQO
EmsisoftJS:Trojan.JS.Agent.RQO (B)
ComodoTrojWare.JS.Agent.ALB@76k77w
F-SecureMalware.HTML/ExpKit.Gen2
FireEyeJS:Trojan.JS.Agent.RQO
IkarusTrojan.JS.Crypt
AviraHTML/ExpKit.Gen2
Antiy-AVLTrojan[Infect]/JS.Agent
MicrosoftTrojan:HTML/Scrinject.C!bit
GDataHTML.Trojan.Kryptik.FG
CynetMalicious (score: 85)
ALYacJS:Trojan.JS.Agent.RQO
ESET-NOD32JS/Kryptik.ALB
RisingTrojan.Kryptik!8.8 (TOPIS:E0:pkvOwOe5cUN)
MAXmalware (ai score=81)
FortinetJS/Kryptik.ALB!tr
AVGJS:Decode-BTB [Trj]
Qihoo-360virus.js.qexvmc.1

How to remove Trojan:HTML/Scrinject.C!bit?

Trojan:HTML/Scrinject.C!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment