Trojan

About “Trojan.Win32.Scar.tjga” infection

Malware Removal

The Trojan.Win32.Scar.tjga is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scar.tjga virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Scar.tjga?


File Info:

name: 0B867B2675C78FCFA113.mlw
path: /opt/CAPEv2/storage/binaries/b03fd8539d32923c2061776932f324d87984a648ed68122c12c4e970c1b201c2
crc32: 4CCB5A29
md5: 0b867b2675c78fcfa113c17abd1e242e
sha1: dcf868fb34bf36759a00ee15520479504101a257
sha256: b03fd8539d32923c2061776932f324d87984a648ed68122c12c4e970c1b201c2
sha512: 045463661738f03009d3e7116136c8507e0ca3c4bc24d859aa156f573fadac983791f2a420932618964aada1d80cb035f87148a17870cdaf6aa7c870d5d6f859
ssdeep: 24576:pRwWA10GpsliirvRwWA10GpBliiC11H2o96Pon:H8Lpoiirp8Lp7iiC7H2oC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T168057CC3A6D484F0CB6D21701B67F77E9B3E9DB1CB5056C6A7D0ED2B28646C07838689
sha3_384: 05ef3015ce2b26988003aec488d8a650a4c1a2b0e4695f9d4938cf9d9dd309f1a6a5b14e4a562deece533d8bfbfa94cd
ep_bytes: e84e050000e939feffffcccccccccccc
timestamp: 2001-08-15 22:27:25

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Command Processor
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: cmd
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Cmd.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Trojan.Win32.Scar.tjga also known as:

LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.0b867b2675c78fcf
McAfeeArtemis!0B867B2675C7
CylanceUnsafe
K7AntiVirusTrojan ( 00561cbf1 )
BitDefenderWin32.Expiro.Gen.6
K7GWTrojan ( 00561cbf1 )
Cybereasonmalicious.675c78
CyrenW32/Expiro.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Virus.Expiro-9891450-0
KasperskyTrojan.Win32.Scar.tjga
AlibabaTrojan:Win32/Raccoon.b9237030
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanWin32.Expiro.Gen.6
Ad-AwareWin32.Expiro.Gen.6
EmsisoftWin32.Expiro.Gen.6 (B)
McAfee-GW-EditionArtemis
SophosMal/EncPk-MK
AviraTR/Patched.Gen
MicrosoftTrojan:Win32/Raccoon.EC!MTB
GDataWin32.Expiro.Gen.6 (2x)
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.520647366
PandaTrj/Genetic.gen
TencentWin32.Virus.Expiro.Hfi
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NS!tr
AVGWin32:Xpirat-C [Inf]
AvastWin32:Xpirat-C [Inf]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Win32.Scar.tjga?

Trojan.Win32.Scar.tjga removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment