Trojan

Trojan.Win32.Scar.ofhn removal

Malware Removal

The Trojan.Win32.Scar.ofhn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scar.ofhn virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Created a service that was not started

How to determine Trojan.Win32.Scar.ofhn?


File Info:

name: 3D19A426992022E7605F.mlw
path: /opt/CAPEv2/storage/binaries/f742c0758d83298e26484c611072aeccaeaa53f54542e790e92e7f7aa9420178
crc32: 436962A8
md5: 3d19a426992022e7605ff112cff95a3f
sha1: 81797e1b3392723f73faf64ad9adc72a826dbb67
sha256: f742c0758d83298e26484c611072aeccaeaa53f54542e790e92e7f7aa9420178
sha512: adcebeabc8b0a32f9ee5ccb535ec11a18d53d0d4ea922aebd11ae9ff059263e2675eeaf52f20343e4265d48ca4e5067f6820942b03424ce00d6af77fd68c6e67
ssdeep: 12288:l8kxNhOZElO5kkWjhD4AcGsGtAtScw3qEKBq8kxNhO:WqEkfFN1457q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C05AF6AF6C08833D3231A78CD5B9678EC66BE903E2955463BF91D0C4F3D38179262D6
sha3_384: c59a83ce63ea72274c0ac0b271a4c7b10768d60a1594618b0b69bc6876887a53472f665e0c637f8de042d1e03cabbebf
ep_bytes: 558bec83c4f033c08945f0b810694500
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Win32.Scar.ofhn also known as:

BkavW32.FasongFTTcA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.42350377
FireEyeGeneric.mg.3d19a426992022e7
CAT-QuickHealWorm.Fasong.S15321194
McAfeeW32/Worm-FGN!3D19A4269920
CylanceUnsafe
VIPREWorm.Win32.Fasong.a (v)
K7AntiVirusTrojan ( 0048b81e1 )
K7GWTrojan ( 0048b81e1 )
CrowdStrikewin/malicious_confidence_90% (D)
BaiduWin32.Trojan-PSW.OLGames.bm
CyrenW32/Trojan.GXUK-2094
SymantecTrojan.Benfgame
ESET-NOD32Win32/Fasong.A.unp
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.ofhn
BitDefenderTrojan.GenericKD.42350377
NANO-AntivirusTrojan.Win32.Fasong.hmzl
AvastWin32:Fasong-G [Wrm]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.GenericKD.42350377
EmsisoftTrojan.GenericKD.42350377 (B)
ComodoWorm.Win32.Fasong.A.unp@295j
DrWebWin32.HLLW.Fasong.1
McAfee-GW-EditionBehavesLike.Win32.Pluto.ch
SophosML/PE-A + Troj/Fasong-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.D469WN
JiangminTrojan/Hiddukel.e
eGambitUnsafe.AI_Score_100%
AviraTR/Fasong.werqs
Antiy-AVLTrojan/Generic.ASMalwS.227F8
ViRobotWorm.Win32.A.Fasong.417282
MicrosoftWorm:Win32/Fasong
AhnLab-V3Worm/Win32.Fasong.R117748
Acronissuspicious
BitDefenderThetaAI:Packer.610A816E21
ALYacTrojan.GenericKD.42350377
MAXmalware (ai score=87)
VBA32TScope.Trojan.Delf
MalwarebytesWorm.Fasong
RisingWorm.Fasong!1.D14C (CLASSIC)
YandexTrojan.GenAsa!hwt41/n6xBs
IkarusWorm.Win32.Fasong
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Fasong.GA!worm
AVGWin32:Fasong-G [Wrm]
PandaTrj/Fasong.F.worm

How to remove Trojan.Win32.Scar.ofhn?

Trojan.Win32.Scar.ofhn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment