Malware

What is “ATK/ScareCrow-A”?

Malware Removal

The ATK/ScareCrow-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ATK/ScareCrow-A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine ATK/ScareCrow-A?


File Info:

name: 7102A25804569A3E6729.mlw
path: /opt/CAPEv2/storage/binaries/8001bfcf21718e709740efdda8283f55e8f62407c66a0a6607b46a13b98fcfe7
crc32: 45AA02CB
md5: 7102a25804569a3e67293e6bf3c04d13
sha1: da29d581da5f79ae56a05a117f17c87fcd96c219
sha256: 8001bfcf21718e709740efdda8283f55e8f62407c66a0a6607b46a13b98fcfe7
sha512: 6026ffd39c7046b06b064128312bd917be80682b2c8d1f64cc85892a3945137d0b69bfb7d5bcbc66ff94d53972ed54a4637638a648cffe70f68f5c939436853a
ssdeep: 49152:4HSPMe3mVQrb/T3vO90dL3BmAFd4A64nsfJgbNTWHb1THHHLyD3n9vYBlkgToDhP:YSX3Bt1DhP
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1EBD5AD43BC9145F9C5AEC2308A6592917A31B8C8073623D72FA1E7F92F76BD41E78364
sha3_384: ad5d3e2f78edb405373d2d120ac4e7ce0dbf0941f90775d6bc9a5dfea0752ba53c6be4f8ca182c7fa4d08fb3636a8631
ep_bytes: 4883ec28488b0585562900c700000000
timestamp: 2021-12-08 20:52:46

Version Info:

FileDescription: Microsoft PowerPoint
FileVersion: 16.0.14326.20404
InternalName: Powerpnt
OriginalFilename: Powerpnt.exe
ProductName: Microsoft Office
ProductVersion: 16.0.14326.20404
Translation: 0x0409 0x04b0

ATK/ScareCrow-A also known as:

MicroWorld-eScanTrojan.GenericKDZ.79465
ALYacTrojan.GenericKDZ.79465
ArcabitTrojan.Generic.D13669
BitDefenderTrojan.GenericKDZ.79465
AvastWin64:Evo-gen [Susp]
Ad-AwareTrojan.GenericKDZ.79465
EmsisoftTrojan.GenericKDZ.79465 (B)
FireEyeTrojan.GenericKDZ.79465
SophosATK/ScareCrow-A
AviraHEUR/AGEN.1145901
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKDZ.79465
CynetMalicious (score: 100)
MalwarebytesTrojan.Meterpreter
AVGWin64:Evo-gen [Susp]

How to remove ATK/ScareCrow-A?

ATK/ScareCrow-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment