Trojan

Trojan:Win32/Scar.L information

Malware Removal

The Trojan:Win32/Scar.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Scar.L virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself

How to determine Trojan:Win32/Scar.L?


File Info:

name: 636570F3E5F472D337F2.mlw
path: /opt/CAPEv2/storage/binaries/856c1b276c828b08de85276913f92a2f195966ab927b19101948f7caac9b7baa
crc32: 65B27232
md5: 636570f3e5f472d337f2d72d3e09241a
sha1: 0a405078cb2b89ea568cf7a2be93f360765c7698
sha256: 856c1b276c828b08de85276913f92a2f195966ab927b19101948f7caac9b7baa
sha512: 4398af4f470974aebd20b15e5d76f09d701c528450dc00b6be681b3ec8c581598d836817a5f74b16e47381cd64563ecc8ab1c3023437b0236ea0da18aff8cf44
ssdeep: 1536:xAAH6WfGwpOyqqah+tMOUvsoAygXMP4mZO5nku3hJTyPaEGQXq:xAixHpAtZ1d4h3hByPa0q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166930201BFE11A3FD5E16CB506DF06468D2C797BADADD212652A2309FF6B30DE258309
sha3_384: 70ac2328e94d89a5cf0d12e0f6155373df7b8a2e78838aed7702047da2bef76084b9806f87857a584d3d4fa7f2e738ea
ep_bytes: 60be001042008dbe0000feff57eb0b90
timestamp: 2005-11-19 21:20:50

Version Info:

Comments:
CompanyName: Foxit Corporation
FileDescription: Foxit Reader 5.0, Best Reader for Everyday Use!
FileVersion: 5, 0, 2, 0718
InternalName: Foxit Reader.exe
LegalCopyright: Copyright (C) 2009-2011 Foxit Corporation
LegalTrademarks:
OriginalFilename: Foxit Reader.EXE
PrivateBuild:
ProductName: Foxit Reader
ProductVersion: 5, 0, 2, 0718
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan:Win32/Scar.L also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Jorik.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Conjar.7
FireEyeGeneric.mg.636570f3e5f472d3
ALYacGen:Heur.Conjar.7
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.53974
K7AntiVirusTrojan ( 003640b31 )
AlibabaTrojan:Win32/Fareit.0b70fb63
K7GWTrojan ( 003640b31 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Fareit.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.OCC
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Conjar.7
NANO-AntivirusTrojan.Win32.Jorik.izzkv
AvastFileRepMalware
TencentWin32.Trojan.Jorik.Wncn
Ad-AwareGen:Heur.Conjar.7
EmsisoftGen:Heur.Conjar.7 (B)
ComodoTrojWare.Win32.Remex.bfjb@4miupi
DrWebTrojan.Packed.22288
VIPREWorm.Win32.Cridex.ba (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
SophosML/PE-A + Mal/Zbot-EZ
IkarusTrojan.Win32.Yakes
GDataGen:Heur.Conjar.7
JiangminTrojan/Jorik.allq
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.AGeneric
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Conjar.7
SUPERAntiSpywareHeur.Agent/Gen-FakeFoxit
MicrosoftTrojan:Win32/Scar.L
AhnLab-V3Trojan/Win32.Remex.R20432
McAfeeArtemis!636570F3E5F4
MAXmalware (ai score=100)
VBA32Trojan.Xtob
YandexTrojan.Agent!bjynjhDallA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3575609.susgen
FortinetW32/Yakes.B!tr
BitDefenderThetaGen:NN.ZexaF.34062.fmKfa87mCRji
AVGFileRepMalware
Cybereasonmalicious.3e5f47
PandaBck/Qbot.AO

How to remove Trojan:Win32/Scar.L?

Trojan:Win32/Scar.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment