Home Malware Programs Trojans Trojan.Win32.Scar.dimu

Trojan.Win32.Scar.dimu

Posted: February 22, 2011

Trojan.Win32.Scar.dimu alters the host computer's registry to enable its own running while the system boots up, and has been confirmed to produce both inbound and outbound traffic. As a Trojan, Trojan.Win32.Scar.dimu infects systems in less visible ways and may not have an obvious outer presence. However, Trojans like Trojan.Win32.Scar.dimu present a high-level security threat due to their ability to run additional malware and monitor computer activity for valuable information to feed back to remote attackers. Removing Trojan.Win32.Scar.dimu quickly by using suitable anti-malware programs will keep the chances of extreme information compromise or system damage low.

What Trojan.Win32.Scar.dimu Gives to Your Computer

Trojan.Win32.Scar.dimu and Trojans just like Trojan.Win32.Scar.dimu are very generous, and will be quite content in dropping more malware programs onto your computer. Other malware may be detected by catching unfamiliar processes in memory or files on your computer, but many will attempt to conceal themselves and shut down security programs. This makes deleting Trojan.Win32.Scar.dimu a race against time to keep Trojan.Win32.Scar.dimu from harming your system with all its spyware and rogue anti-virus infections acquaintances.

If you believe your computer is infected with Trojan.Win32.Scar.dimu, you should pay attention to suspicious or unusual error messages or desktop alerts, since these may be deceptions to get you to install other malware. The downloading activities produced by Trojan.Win32.Scar.dimu will also use system resources, which can heavily interfere with the use of your computer.

...And What Trojan.Win32.Scar.dimu Takes

This Trojan's activities aren't limited to downloading files, however. Trojan.Win32.Scar.dimu has also been verified to produce outbound traffic as well, and may monitor your information and activities and send that information to remote attackers. This can compromise your identity and online accounts and may result in serious fraud or identity theft issues.

Another possibility that Trojan.Win32.Scar.dimu's presence allows is that of a potential direct attack by the remote attacker. Interferences caused by remote attackers are hardly limited to just spying; online criminals can also control your computer and force it to perform illegal actions such as DDoS attacks, or they may choose to damage it to the point of a total system wipe being required.

Trojan.Win32.Scar.dimu isn't necessarily very original in its two main attacks on infected computers, but it doesn't have to be - the attacks Trojan.Win32.Scar.dimu uses remain highly effective against unprotected systems. Remove Trojan.Win32.Scar.dimu with a good anti-malware scanner when a scan comes up with this little invader, and you'll be preventing a world of harm that would have come to you later.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\data.dat
    2 %AppData%\Kernel32.exe
    3 %AppData%\Microsoft\Windows Defender
    4 %Temp%\Crack.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EfgbvmuHKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{A2998CCB-DD4A-417B-C0BA-EF0DC84CB58A}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CEBE7B8F-CEBE-7B8F-CEBE-7B8FCEBE7B8F}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CEBE7B8F-CEBE-7B8F-CEBE-7B8FCEBE7B8F}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CEBE7B8F-CEBE-7B8F-CEBE-7B8FCEBE7B8F}\ProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CEBE7B8F-CEBE-7B8F-CEBE-7B8FCEBE7B8F}\VersionIndependentProgIDHKEY_LOCAL_MACHINE\SOFTWARE\LicensesHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A2998CCB-DD4A-417B-C0BA-EF0DC84CB58A}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ExplorerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run
Loading...