Trojan

Trojan.Win32.Scar.szbd removal instruction

Malware Removal

The Trojan.Win32.Scar.szbd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scar.szbd virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

iplogger.org
apps.identrust.com
filelss08.top

How to determine Trojan.Win32.Scar.szbd?


File Info:

crc32: 40044593
md5: c3f86f1a3290c5b78683c7fb7dd44488
name: tmpo8g96tjd
sha1: 8c8dd6edf11064c8e8291f78bb6bf78e8649947c
sha256: 35ec7e1f8a0943e24a53243fcdb94afbc7cd688779143192d8f3aff301cea7aa
sha512: f6d87578a18153192551be961e49db356d0d584b377b8440752a368b053013cd0849b42bc0aa4809040bd40f6e987bbadb34062cdd53500216f2b6399b9d6a3a
ssdeep: 12288:Mewu4RabM41qvHWuVIfsFUun6CH8VCUXXNx1iC0AhRAxVbTZpa7rSA:112Nv2qIOUJCRU4C0Ahkcr7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalNamed: eczvjphvesv.ixe
FileVersionOld: 1.2.0.1
ProductVersion: 1.0.4.1
Copyrighd: Copyrighd (C) 2020, odfgbiv
Translation: 0x0842 0x04c4

Trojan.Win32.Scar.szbd also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.43361279
FireEyeGeneric.mg.c3f86f1a3290c5b7
McAfeeRDN/Generic.rp
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 004f4a0a1 )
BitDefenderTrojan.GenericKD.43361279
K7GWAdware ( 004f4a0a1 )
Cybereasonmalicious.df1106
TrendMicroTROJ_GEN.R03BC0RFJ20
F-ProtW32/Wacatac.BV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
ClamAVWin.Malware.Generic-8119045-0
GDataTrojan.GenericKD.43361279
KasperskyTrojan.Win32.Scar.szbd
AlibabaTrojan:Win32/GandCrypt.9cca3f0d
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.43361279 (B)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.jc
Trapminesuspicious.low.ml.score
SophosMal/GandCrab-G
CyrenW32/Wacatac.BV.gen!Eldorado
WebrootW32.Trojan.Gen
ArcabitTrojan.Generic.D295A3FF
ZoneAlarmTrojan.Win32.Scar.szbd
MicrosoftTrojan:Win32/CryptInject.RBA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R340930
Acronissuspicious
ALYacTrojan.GenericKD.43361279
MAXmalware (ai score=86)
Ad-AwareTrojan.GenericKD.43361279
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HEEX
TrendMicro-HouseCallTROJ_GEN.R03BC0RFJ20
TencentWin32.Trojan.Scar.Taey
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Kryptik.HEDU!tr
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.193

How to remove Trojan.Win32.Scar.szbd?

Trojan.Win32.Scar.szbd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment