Trojan

Should I remove “TrojanDownloader:MSIL/Scarsi.RS!MTB”?

Malware Removal

The TrojanDownloader:MSIL/Scarsi.RS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:MSIL/Scarsi.RS!MTB virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine TrojanDownloader:MSIL/Scarsi.RS!MTB?


File Info:

name: 15B64DE21D36A10F789B.mlw
path: /opt/CAPEv2/storage/binaries/4dd8a156889052182a622c8312385431d4da795cd831698f03aeab8c4d3873ea
crc32: 87C5C6C8
md5: 15b64de21d36a10f789bfd52fe23b81b
sha1: 7e66354c8e60b3b0938e660f5041fa6afa7130b0
sha256: 4dd8a156889052182a622c8312385431d4da795cd831698f03aeab8c4d3873ea
sha512: 1b791a1271a42b23f8ab8aede9544bc992bab84aa8c8620d44c7f93f497a106cb65702bd4dd65fd1cc126e46ff93438276a71df0c24bb6bc61d6be28f2f2ad40
ssdeep: 384:kcB25qLgxoYGc4lRozeoH+b/i7optYcFmVc03KJ:kcYggxWqz3ebK8tYcFmVc6KJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174726C02A2C40172EA31077A39675F86DB3B962B19B78B9E744C414E3F37B1287237E5
sha3_384: d481728557a24261bc0d934732e6b9bd436de17755206ccd68dccf5c80195db17970de8a5637bb14eb565429167c34aa
ep_bytes: ff250020400000000000000000000000
timestamp: 2075-07-27 08:33:21

Version Info:

Translation: 0x0000 0x04b0
Comments: Audacity 3.1.3 Setup
CompanyName: Audacity Team
FileDescription: Audacity 3.1.3 Setup
FileVersion: 3.1.3.0
InternalName: MEMEM11Mewlsrpdyms.exe
LegalCopyright: Copyright © 2018. All rights reserved.
LegalTrademarks:
OriginalFilename: MEMEM11Mewlsrpdyms.exe
ProductName: Audacity
ProductVersion: 3.1.3.0
Assembly Version: 3.1.3.0

TrojanDownloader:MSIL/Scarsi.RS!MTB also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
FireEyeGeneric.mg.15b64de21d36a10f
SkyhighGenericRXUO-AP!15B64DE21D36
McAfeeGenericRXUO-AP!15B64DE21D36
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0059c9381 )
AlibabaTrojanDownloader:MSIL/Scarsi.5af2ac52
K7GWTrojan-Downloader ( 0059c9381 )
ArcabitIL:Trojan.MSILZilla.D5CD0
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.NYO
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Scarsi.gen
BitDefenderIL:Trojan.MSILZilla.23760
MicroWorld-eScanIL:Trojan.MSILZilla.23760
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.116049fc
EmsisoftIL:Trojan.MSILZilla.23760 (B)
F-SecureHeuristic.HEUR/AGEN.1311216
DrWebTrojan.DownLoader45.28819
TrendMicroTrojan.MSIL.SCARSI.R03BC0DKC22
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.anrpk
WebrootW32.Trojan.GenKD
GoogleDetected
AviraHEUR/AGEN.1311216
Antiy-AVLTrojan/MSIL.Scarsi
Kingsoftmalware.kb.c.998
MicrosoftTrojanDownloader:MSIL/Scarsi.RS!MTB
ZoneAlarmHEUR:Trojan.MSIL.Scarsi.gen
GDataMSIL.Trojan-Downloader.Agent.BJF
VaristW32/MSIL_Agent.EML.gen!Eldorado
AhnLab-V3Ransomware/Win.Mallox.C5290232
VBA32Downloader.MSIL.gen.rexp
ALYacIL:Trojan.MSILZilla.23760
MAXmalware (ai score=89)
MalwarebytesMalware.AI.1773846813
PandaTrj/Chgt.AA
TrendMicro-HouseCallTrojan.MSIL.SCARSI.R03BC0DKC22
RisingDownloader.Agent!8.B23 (CLOUD)
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.73692792.susgen
FortinetMSIL/Agent.LYC!tr
BitDefenderThetaGen:NN.ZemsilF.36804.bm1@aW1p!Nc
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:MSIL/Scarsi.RS!MTB?

TrojanDownloader:MSIL/Scarsi.RS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment