Trojan

Should I remove “Trojan:Win32/Prepscram!pz”?

Malware Removal

The Trojan:Win32/Prepscram!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Prepscram!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Prepscram!pz?


File Info:

name: FD55B2B8686643B47341.mlw
path: /opt/CAPEv2/storage/binaries/31d83a7b5a708f6272fb880c0a5f42a8c45d4c4f0ac0e20989a565651f5f0940
crc32: 347E29D5
md5: fd55b2b8686643b47341423fd3681c45
sha1: b54880d79a74351fc25b1fd6100254ba839452d1
sha256: 31d83a7b5a708f6272fb880c0a5f42a8c45d4c4f0ac0e20989a565651f5f0940
sha512: 3fca548e3a54e2acbbbaa85a13c4415523215257530a73c94e581534e2be7f3719c3017d0aaefe9ad6d69c95b1681e4f5156526530006c4d07ad1f57a2686fd7
ssdeep: 12288:jG22kiw9efjQkWOTWnsF71zNc5O+TW/bKnGnXqTb7L:jG22kBQrVjFZNl2WoG6H/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FDF45B37EC04F77AC02A20B5F0D60B662647E698C3F9E9C6F5CDE134D9AD640EA11978
sha3_384: 8372f59e02a2b6da32e12b7970b0cc893276106af5f9f52e8409f38b80c0866d13e272772a0a7b1bda5d1e4b7475e74a
ep_bytes: 60be00f040008dbe0020ffff57eb0b90
timestamp: 2015-05-05 13:45:31

Version Info:

0: [No Data]

Trojan:Win32/Prepscram!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.tpMQ
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.DNSR
ClamAVWin.Malware.Zusy-9957983-0
FireEyeGeneric.mg.fd55b2b8686643b4
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.bh
McAfeeArtemis!FD55B2B86866
VIPRETrojan.Agent.DNSR
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Agent.4ab
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Agent.DNSR
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.NCK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.neyndy
BitDefenderTrojan.Agent.DNSR
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
AvastWin32:FileinfectorX-gen [Trj]
TencentTrojan.Win32.Agent.han
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.DownLoader23.51365
ZillyaTrojan.Agent.Win32.1019202
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.DNSR (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Spy.Gen
Kingsoftmalware.kb.b.996
XcitiumHeur.Corrupt.PE@1z141z3
MicrosoftTrojan:Win32/Prepscram!pz
ZoneAlarmTrojan.Win32.Agent.neyndy
GDataTrojan.Agent.DNSR
VaristW32/Agent.FWC.gen!Eldorado
Acronissuspicious
BitDefenderThetaAI:Packer.0F3D5E541F
ALYacTrojan.Agent.DNSR
MAXmalware (ai score=85)
VBA32Trojan.Agent
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingVirus.Agent!8.9D (CLOUD)
IkarusTrojan.Win32.Prepscram
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.NCK
AVGWin32:FileinfectorX-gen [Trj]

How to remove Trojan:Win32/Prepscram!pz?

Trojan:Win32/Prepscram!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment