Trojan

Trojan.Win32.Scar.cwhu removal guide

Malware Removal

The Trojan.Win32.Scar.cwhu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scar.cwhu virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Trojan.Win32.Scar.cwhu?


File Info:

name: 6ABD7EFB7E20892BCB46.mlw
path: /opt/CAPEv2/storage/binaries/7fb896e65abcf4f882cd460e7d67764511d9a33c4d7235b6e39e900e10113a6b
crc32: ACBB741D
md5: 6abd7efb7e20892bcb46cf68a393273a
sha1: 7f078dc2508f41f04355841771a793ff6403126c
sha256: 7fb896e65abcf4f882cd460e7d67764511d9a33c4d7235b6e39e900e10113a6b
sha512: 94603be431ed29ad5d64c2a937d82cf34dc9c673b441645c22209d01c587f62e3e9b2aec311b7a6135f5839953c3df7d7390095b28276c5a67e0b338d2ced84d
ssdeep: 12288:zGOeDCBxhAyaxJ1cfJQ0vgt5Xfx2NLUty3lYM6BIUOk8qI0A:zG/eVAzJsm0vUp+LRYMlKA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1D423B2202D5963CBF9C5F2E67A2344CBBA17119B12F89F00FEB04ED45077E2E89556
sha3_384: 6a1c8446bc05832ef3dc01e5593affdd93563c39bb42d952519600b3fbd2c02816427abfb8d6b6c0afd0df838260c14f
ep_bytes: 60be00e04e008dbe0030f1ff57eb0190
timestamp: 2010-08-20 22:29:47

Version Info:

0: [No Data]

Trojan.Win32.Scar.cwhu also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Mint.SP.Sneaky.1
ALYacGen:Heur.Mint.SP.Sneaky.1
CylanceUnsafe
SangforTrojan.Win32.Scar.buxin
AlibabaTrojan:Win32/Generic.d79b24f1
Cybereasonmalicious.b7e208
VirITTrojan.Win32.SHeur3.BCRC
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
ClamAVWin.Trojan.Agent-1083515
KasperskyTrojan.Win32.Scar.cwhu
BitDefenderGen:Heur.Mint.SP.Sneaky.1
NANO-AntivirusTrojan.Win32.Scar.kkwrh
AvastWin32:Trojan-gen
TencentWin32.Trojan.Scar.Wrqz
Ad-AwareGen:Heur.Mint.SP.Sneaky.1
TACHYONTrojan/W32.Scar.601600.E
EmsisoftGen:Heur.Mint.SP.Sneaky.1 (B)
ComodoMalware@#3j7a1yc34wymb
DrWebTrojan.MulDrop2.35996
ZillyaTrojan.Scar.Win32.43575
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.6abd7efb7e20892b
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.SP.Sneaky.1
JiangminTrojan/Scar.abjq
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
ArcabitTrojan.Mint.SP.Sneaky.1
ZoneAlarmTrojan.Win32.Scar.cwhu
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!6ABD7EFB7E20
MAXmalware (ai score=100)
VBA32suspected of Trojan.Downloader.gen
RisingTrojan.Bulta!8.35D (CLOUD)
YandexTrojan.GenAsa!Oec5t/h8AWY
IkarusGen.Mint
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Scar.CWHU!tr
BitDefenderThetaAI:Packer.13404C191E
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Scar.cwhu?

Trojan.Win32.Scar.cwhu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment