Trojan

Trojan.Win32.Scar.ofru information

Malware Removal

The Trojan.Win32.Scar.ofru is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scar.ofru virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan.Win32.Scar.ofru?


File Info:

name: 997CC324BDD36C3BB3F0.mlw
path: /opt/CAPEv2/storage/binaries/5e835d6dde621114226138c4f44266c1c8c1d0e23f1e0cc117bd65c5b7bc1e6f
crc32: 5F534D2A
md5: 997cc324bdd36c3bb3f08dce342dba73
sha1: 056b0a8dd0c549f74ea7d76e8657d91d0cb85253
sha256: 5e835d6dde621114226138c4f44266c1c8c1d0e23f1e0cc117bd65c5b7bc1e6f
sha512: 887553ff37a6d613a6b2c8abb8ae07a05a4c6302c132d0cb7b6012911b28164b4aa1c3317fc35a86d872456db8033085ab4592c11dd6c5bcc5b53bc45208243d
ssdeep: 12288:LUyI6hJQglQA0IWb8DmPySxEuBZDxywHBlP94jpguwDxXlZ1nr4:dVh6gl6Iy8R9+ZdnnP94jpgl9Bnr4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18FE4F1216180C038F3AA077689A2E1E51A297D785790E58FF7E87DB65A311D79B3330F
sha3_384: 92bae5ee96f93935099c1a5e0dcae98d9e89efeb0195bfa2bd3f6fa9504bddddcade65936edd966de80b2c0e81c5da7a
ep_bytes: e81a690000e917feffff558bec81ec28
timestamp: 2013-07-29 06:23:43

Version Info:

0: [No Data]

Trojan.Win32.Scar.ofru also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
CAT-QuickHealTrojan.Gupboot.G.mue
CylanceUnsafe
VIPRETrojan.Win32.Urelas.ab (v)
K7AntiVirusBackdoor ( 0053e8561 )
K7GWBackdoor ( 0053e8561 )
Cybereasonmalicious.4bdd36
BaiduWin32.Rootkit.Agent.s
CyrenW32/Urelas.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.V
APEXMalicious
ClamAVWin.Malware.Urelas-9655843-0
KasperskyTrojan.Win32.Scar.ofru
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.ccrgux.eaqeei
AvastMBR:Plite-I [Rtk]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Heur.Mint.SP.Urelas.1
SophosML/PE-A + Troj/Urelas-Q
ComodoTrojWare.Win32.Urelas.DAQ@5qwr5f
DrWebTrojan.AVKill.32484
ZillyaTrojan.Jorik.Win32.252559
McAfee-GW-EditionBehavesLike.Win32.Corrupt.jc
FireEyeGeneric.mg.997cc324bdd36c3b
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.N1LLQM
JiangminTrojan/Jorik.hpkh
AviraHEUR/AGEN.1123985
Antiy-AVLTrojan/Generic.ASMalwS.37E09B
MicrosoftTrojan:Win32/Urelas.AA
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Plite.C4576070
Acronissuspicious
McAfeeCorrupt-FY!997CC324BDD3
MAXmalware (ai score=88)
VBA32Trojan.Scar
MalwarebytesMalware.AI.1913632395
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexTrojan.GenAsa!4Uy3npMQvd4
FortinetW32/Swisyn.PFG!tr
BitDefenderThetaAI:Packer.B7BEDF5721
AVGMBR:Plite-I [Rtk]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Scar.ofru?

Trojan.Win32.Scar.ofru removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment