Home Malware Programs Trojans Scar.gen.j

Scar.gen.j

Posted: May 14, 2010

Scar.gen.j is a malicious Trojan that replaces files on the infected computer with corrupt files. Scar.gen.j will also drop an Autorun.Inf file on removable USB drives, shared drives and root of all local drives and system folders. Scar.gen.j poses a risk to system security and should be removed immediately once detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\ntldr.exe
    2 C:\WinNT.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Data: NT4 hosting service = "%System%\ntldr.exe"Data: NoDriveAutoRun = 0*00000000Data: NoDriveTypeAutoRun = 0*00000000HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Run]Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\policies\Explorer
Loading...