Trojan

What is “Trojan.Win32.Scar.ernd”?

Malware Removal

The Trojan.Win32.Scar.ernd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scar.ernd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Scar.ernd?


File Info:

name: E0C750FA642C71E9D717.mlw
path: /opt/CAPEv2/storage/binaries/f781e8c8d51f51b8c2cf5ea46905cfab11ad0b15d38b5845d64ff0ea82f72db0
crc32: 9C324733
md5: e0c750fa642c71e9d717c469c9e0b40a
sha1: 43e9347a13cf26d7088ece40be10985853b8c238
sha256: f781e8c8d51f51b8c2cf5ea46905cfab11ad0b15d38b5845d64ff0ea82f72db0
sha512: e3091fc7a4453ea87332e8f6ea5e39eded470c2d45be8b1404ffaf5b8112fb243e706f2e25e1eda3ab0154519fca0bcd720330b317e4b5ac45248f16fbbe2a0b
ssdeep: 1536:Q7wVFjb7ebUBtizWywMsK8q72QNSqxAASKrSitUrN4oQ/hKeXsjEFXNo:QgnBtiJ772QNPPSK24oQZiEVC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0D3E5293291E23ED529CBF42E5A83E490ADAC3521D6B81BF7C55B0273F2D578360B53
sha3_384: 614a76eebbc6b79bf629cc8e648489639ef78c6f83ee8be9bedecf2ad2501466f8e9090e12e71ea95937ae99695d20e7
ep_bytes: 68cc324000e8f0ffffff000000000000
timestamp: 1995-08-10 23:46:21

Version Info:

Translation: 0x0409 0x04b0
ProductName: RfBxbhsamLO
FileVersion: 1.00
ProductVersion: 1.00
InternalName: gzlozvjF
OriginalFilename: gzlozvjF.exe

Trojan.Win32.Scar.ernd also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.low6
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.60
MicroWorld-eScanGen:Trojan.Sresmon.Gen.1
CAT-QuickHealTrojan.Vobfus.gen
McAfeeVBObfus.eq
MalwarebytesMalware.AI.1160291973
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 002de3871 )
AlibabaWorm:Win32/Vobfus.a781ac51
K7GWP2PWorm ( 002de3871 )
Cybereasonmalicious.a642c7
BitDefenderThetaAI:Packer.715549FB1F
VirITTrojan.Win32.Generic.BIRQ
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup!gen35
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.AFV
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Scar.ernd
BitDefenderGen:Trojan.Sresmon.Gen.1
NANO-AntivirusTrojan.Win32.Scar.cniokg
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
F-SecureWorm.WORM/Vobus.N.4
BaiduWin32.Worm.Pronny.d
VIPREGen:Trojan.Sresmon.Gen.1
TrendMicroWORM_VOBFUS.SMHE
Trapminemalicious.high.ml.score
SophosMal/VB-UY
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraWORM/Vobus.N.4
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Diple.EMIB@4pez3w
ArcabitTrojan.Sresmon.Gen.1
ViRobotTrojan.Win32.A.Scar.135168
ZoneAlarmTrojan.Win32.Scar.ernd
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C127440
VBA32BScope.Trojan.Diple
MAXmalware (ai score=89)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Vobfus!1.99C7 (CLASSIC)
YandexTrojan.GenAsa!aqWYuVmFOt0
IkarusWorm.Win32.WBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Scar.ernd?

Trojan.Win32.Scar.ernd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment