Trojan

About “Trojan.Win32.Scar.ofmc” infection

Malware Removal

The Trojan.Win32.Scar.ofmc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scar.ofmc virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Scar.ofmc?


File Info:

name: FCBDF4E72ED078BFD3F8.mlw
path: /opt/CAPEv2/storage/binaries/c9cd66573751a268b5812ab2061f5e730fc413c22f21832d383bc5d48b2d25d1
crc32: 0605738A
md5: fcbdf4e72ed078bfd3f8f31ac670e6dc
sha1: 8ae5cc4cceaf26922259b12a2493b6eca68202f8
sha256: c9cd66573751a268b5812ab2061f5e730fc413c22f21832d383bc5d48b2d25d1
sha512: e91133b07bd9097199539d830edc6e3e7ec040feefeb5a423217a04dfdcf06189bf6a1fcb2c95e54f2717ce41cd3ad52966e276d54fb1a83922350a5632b7a6b
ssdeep: 6144:TOAztL6W+JJMPkZ5tJb52Wd83erDPKmjxTz7HbYcPCVYhg+KZZ:TOMFwMPkDH/QiPLxvzblu2FK7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139640126E6289954F3190B7A1A4AF6C04D8F6D3D70D6E60EF07CBD326832183567798F
sha3_384: 994eb83c60cc1cbaa8e8580384e61032f36ebae004bb4e877aa68f8fae8979fa62935db503a4117c714eec58bca225d7
ep_bytes: 60e8000000005b8d5bc6011b8b138d73
timestamp: 2013-09-03 12:50:21

Version Info:

0: [No Data]

Trojan.Win32.Scar.ofmc also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.33020
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Gupboot.G.mue
McAfeeGenericRXTZ-TH!FCBDF4E72ED0
MalwarebytesCardSpy.Spyware.Stealer.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0048f6021 )
K7GWTrojan ( 0048f6021 )
Cybereasonmalicious.72ed07
BitDefenderThetaAI:Packer.3BF172A91D
CyrenW32/Urelas.EE.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Urelas.S
APEXMalicious
ClamAVWin.Malware.Urelas-9957614-0
KasperskyTrojan.Win32.Scar.ofmc
BitDefenderGen:Trojan.Heur.tiY@rThXtuiiy
MicroWorld-eScanGen:Trojan.Heur.tiY@rThXtuiiy
AvastWin32:Dropper-gen [Drp]
TencentTrojan.Win32.Scar.xk
EmsisoftGen:Trojan.Heur.tiY@rThXtuiiy (B)
F-SecureBackdoor.BDS/Backdoor.Gen7
BaiduWin32.Rootkit.Agent.s
VIPREGen:Trojan.Heur.tiY@rThXtuiiy
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fcbdf4e72ed078bf
SophosTroj/Urelas-Q
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.XIKXA5
JiangminBackdoor/Plite.k
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen7
MAXmalware (ai score=87)
Antiy-AVLTrojan[Backdoor]/Win32.Plite
XcitiumPacked.Win32.MNSP.Gen@2697wr
ArcabitTrojan.Heur.EDC8D8
ZoneAlarmTrojan.Win32.Scar.ofmc
MicrosoftTrojan:Win32/Urelas.AA
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R81457
VBA32BScope.Trojan.AVKill
ALYacGen:Trojan.Heur.tiY@rThXtuiiy
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Urelas!8.1F5 (TFE:1:qj8HU2xh2fL)
YandexTrojan.GenAsa!0QwPqoenn5Q
IkarusBackdoor.Win32.Plite
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AC.5E8D2!tr
AVGWin32:Dropper-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Scar.ofmc?

Trojan.Win32.Scar.ofmc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment