Trojan

Trojan.ScarPMF.S20592332 malicious file

Malware Removal

The Trojan.ScarPMF.S20592332 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ScarPMF.S20592332 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.ScarPMF.S20592332?


File Info:

name: 7CE175F71AADC3CAA30F.mlw
path: /opt/CAPEv2/storage/binaries/d63d97c1dc6c34fe7f441cb50bbdc7347aa06369b55b7ce261484e6449e25d51
crc32: 59D677F5
md5: 7ce175f71aadc3caa30f6b702f859c89
sha1: e521a9ecac596e06d3e550e0a141f4161218c88c
sha256: d63d97c1dc6c34fe7f441cb50bbdc7347aa06369b55b7ce261484e6449e25d51
sha512: aa8388abac30ef0ea855a40578d23919c3b2d033d24ea16cc3ed2d522f6b2173462bf9926149241d77289573db37d26ea665b4888cc8397f329608e250f57f44
ssdeep: 6144:c1bYec5C8AAYLxhEmPG7qwmioqVsCqbN0P:MUyI6QmPPPqVspM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6749D216141C039F3A6077589A2E0E54A247D7817A5E8CFF6E87D756A321E7AB3330F
sha3_384: 2b2414bb2ef9fb6c837ff2c28909364be040fceb5d35689ded0da58893b3a43d9aab91951e1c00dcff49f2c463db61c6
ep_bytes: e81a690000e917feffff558bec81ec28
timestamp: 2013-07-31 06:46:16

Version Info:

0: [No Data]

Trojan.ScarPMF.S20592332 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Scar.4!c
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
ClamAVWin.Malware.Urelas-9655843-0
FireEyeGeneric.mg.7ce175f71aadc3ca
CAT-QuickHealTrojan.ScarPMF.S20592332
McAfeeCorrupt-FY!7CE175F71AAD
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Jorik.Win32.252559
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
AlibabaBackdoor:Win32/Urelas.2bcd
K7GWBackdoor ( 0053e8561 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36662.wiX@aiX0WAhO
CyrenW32/Urelas.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Urelas.V
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.ofru
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.ccrgux.eaqeei
AvastMBR:Plite-I [Rtk]
TencentTrojan.Win32.Urelas.16000132
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
BaiduWin32.Rootkit.Agent.s
F-SecureTrojan.TR/Urelas.dfarj
DrWebTrojan.AVKill.32484
VIPREGen:Heur.Mint.SP.Urelas.1
TrendMicroTROJ_GEN.R002C0DIG23
McAfee-GW-EditionBehavesLike.Win32.Corrupt.fh
Trapminesuspicious.low.ml.score
SophosTroj/Urelas-Q
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.SG5RVV
JiangminTrojan/Jorik.hpkh
AviraTR/Urelas.dfarj
MAXmalware (ai score=80)
Antiy-AVLTrojan[Downloader]/Win32.Urelas.ab
XcitiumTrojWare.Win32.Urelas.BK@5ol715
ArcabitTrojan.Mint.SP.Urelas.1
ZoneAlarmTrojan.Win32.Scar.ofru
MicrosoftTrojan:Win32/Urelas.WE!MTB
VBA32Trojan.Scar
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DIG23
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexTrojan.GenAsa!4Uy3npMQvd4
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Swisyn.PFG!tr
AVGMBR:Plite-I [Rtk]
Cybereasonmalicious.cac596
DeepInstinctMALICIOUS

How to remove Trojan.ScarPMF.S20592332?

Trojan.ScarPMF.S20592332 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment