Trojan

Trojan.Win32.Scar.kkwr removal guide

Malware Removal

The Trojan.Win32.Scar.kkwr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scar.kkwr virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Starts servers listening on 0.0.0.0:7171
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

zz-dns.com
yy-dns.com

How to determine Trojan.Win32.Scar.kkwr?


File Info:

crc32: C2D889D9
md5: 06cc0fe5d6857e6960d4b1a8161372fa
name: 06CC0FE5D6857E6960D4B1A8161372FA.mlw
sha1: 1b4f04feea12d5bf229feeceb00bb53ca6702701
sha256: 5aca00bad10f4d69ae23254504721d437da01633cfac68de4affa051fe398de1
sha512: fc99e2f85f4d90f524380b00318cf7c58fb1f4ab7e4e0681a290ec642bcaaa7d659ecc9779a94a91179c9df3e29ff259b2cdd6adfdc8c724025f9be37759fcc9
ssdeep: 768:4dpn3AGKlAGmk70Qob4lpMXZG6id0RRTTF:4dx8KrXZNid0RRTTF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Scar.kkwr also known as:

K7AntiVirusTrojan ( 000906541 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Proxy.6334
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Converton.8
CylanceUnsafe
ZillyaTrojan.Tinxy.Win32.119
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Tinxy.cfb875f3
K7GWTrojan ( 000906541 )
Cybereasonmalicious.5d6857
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Tinxy.AD
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Scar.kkwr
BitDefenderGen:Variant.Ransom.Converton.8
NANO-AntivirusTrojan.Win32.BHO.ecnvld
MicroWorld-eScanGen:Variant.Ransom.Converton.8
TencentWin32.Trojan.Scar.Gvs
Ad-AwareGen:Variant.Ransom.Converton.8
SophosMal/Behav-150
ComodoMalware@#iyh4312uvzys
BitDefenderThetaGen:NN.ZexaF.34170.bmW@a8pKMmn
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Koob-3
McAfee-GW-EditionBehavesLike.Win32.Worm.mm
FireEyeGeneric.mg.06cc0fe5d6857e69
EmsisoftGen:Variant.Ransom.Converton.8 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Scar.fqz
AviraTR/BHO.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.26A1BD2
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojanProxy:Win32/Koobface.gen!B
GDataGen:Variant.Ransom.Converton.8
Acronissuspicious
McAfeeArtemis!06CC0FE5D685
MAXmalware (ai score=100)
VBA32BScope.Trojan.Proxy
PandaTrj/CI.A
TrendMicro-HouseCallMal_Koob-3
RisingTrojan.Tinxy!1.685E (CLASSIC)
YandexTrojan.GenAsa!354SvlwuK38
IkarusWin32.Worm.Koobface
FortinetW32/Tinxy.AD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Scar.kkwr?

Trojan.Win32.Scar.kkwr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment