Trojan

Trojan.Win32.Scarsi.pef information

Malware Removal

The Trojan.Win32.Scarsi.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Scarsi.pef virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Win32.Scarsi.pef?


File Info:

crc32: 7D87A93D
md5: 2c4d7c971108ed86eb6809e30acb4f4d
name: 2C4D7C971108ED86EB6809E30ACB4F4D.mlw
sha1: 47b24094fedff1e9b7f5980abf0ae665ce32c205
sha256: 9912a9f74f26e7f3270e8652131afe55d60aba52848974f127e46d162f6701f3
sha512: 952ebad5949276ea76cc9cf6d32d584a6b477c6d744a704870751f390c77062cdfb09da25d7218d309d4707e53b9009b30088270154e451bcfa72366bb4cd61e
ssdeep: 12288:fLC9uyUu76jS8hqezXHN9rt1bffZw2jkJohPCMwrA7W2FeDSIGVH/KIDgDgUeHbe:fkgxgkjvbffYk1QDbGV6eH81k+
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2018
InternalName: unpack200
FileVersion: 8.0.1810.13
Full Version: 1.8.0_181-b13
CompanyName: Oracle Corporation
ProductName: Java(TM) Platform SE 8
ProductVersion: 8.0.1810.13
FileDescription: Java(TM) Platform SE binary
OriginalFilename: unpack200.exe
Translation: 0x0000 0x04b0

Trojan.Win32.Scarsi.pef also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.336579
FireEyeGeneric.mg.2c4d7c971108ed86
McAfeePWS-FCRX!2C4D7C971108
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Variant.Zusy.336579
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_100% (D)
TrendMicroTrojanSpy.Win32.AVEMARIA.SMTH
BitDefenderThetaAI:Packer.BCE7A70017
CyrenW32/Trojan.FQJ.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Injector.ELDH
TrendMicro-HouseCallTrojanSpy.Win32.AVEMARIA.SMTH
AvastSf:ShellCode-CU [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Scarsi.pef
AlibabaTrojanPSW:Win32/Mocrt.80a9cc6c
APEXMalicious
TencentMalware.Win32.Gencirc.10b85aea
Ad-AwareGen:Variant.Zusy.336579
SophosTroj/Agent-AJFK
F-SecureHeuristic.HEUR/AGEN.1121064
DrWebTrojan.Siggen6.54687
InvinceaML/PE-A + Troj/Agent-AJFK
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Variant.Zusy.336579 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dsqqe
AviraHEUR/AGEN.1121064
Antiy-AVLTrojan[Spy]/Win32.AveMaria
MicrosoftPWS:Win32/Mocrt.A!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Zusy.D522C3
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AhnLab-V3Trojan/Win32.Agent.R251631
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.PSE.1L57YIV
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Zusy.336579
MAXmalware (ai score=89)
MalwarebytesSpyware.LokiBot
ZonerTrojan.Win32.97652
RisingStealer.AveMaria!1.CEBB (CLASSIC)
YandexTrojan.GenAsa!3PeokibywzU
IkarusTrojan-Spy.LokiBot
eGambitTrojan.Generic
FortinetW32/Injector.ELDH!tr
AVGSf:ShellCode-CU [Trj]
Cybereasonmalicious.71108e
Qihoo-360Generic/HEUR/QVM19.1.463B.Malware.Gen

How to remove Trojan.Win32.Scarsi.pef?

Trojan.Win32.Scarsi.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment