Home Malware Programs Trojans Scar

Scar

Posted: December 1, 2009

Threat Metric

Ranking: 4,737
Threat Level: 8/10
Infected PCs: 24,037
First Seen: December 1, 2009
Last Seen: October 14, 2023
OS(es) Affected: Windows

Scar is a Trojan that invades your system and may perform multiple damaging functions. Scar can function as a Trojan downloader f, installing additional malware on a targeted computer or as a launcher for another threatening program, which will be downloaded with Scar. Scar can be detected by numerous names, depending on the security program that found it.

When inside a computer, the affected users will start noticing the presence of various malware kinds since these harmful applications' actions will interfere with the good performance of the device. Every malware consumes large quantities of the machine's resources.

If you notice any symptoms that are pointing to the presence of this threatening Trojan, scan your computer with a trustable malware removal product to get rid of Scar as soon as possible.

Aliases

BackDoor.Generic13.FSD [AVG]Backdoor.Win32.Beastdoor [Ikarus]BehavesLike.Win32.Malware.eah (mx-v) [Sunbelt]Win-Trojan/Antisb.190976.F [AhnLab-V3]Trojan/Win32.Agent [Antiy-AVL]Win32/Spyrat.B [eTrust-Vet]Heuristic.BehavesLike.Win32.CodeInjection.A [McAfee-GW-Edition]BDS/Hupigon.Gen [AntiVir]BackDoor.IRC.Bot.355 [DrWeb]Heur.Packed.Unknown [Comodo]Mal/Inject-K [Sophos]Gen:Trojan.Heur.DP.lGW@auEp90k [BitDefender]Trojan.Win32.Scar.cwlm [Kaspersky]Trojan.Hupigon-28458 [ClamAV]Win32:Delf-NSG [Avast]
More aliases (235)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\RDB\Registrytasksys.exe File name: Registrytasksys.exe
Size: 2.99 MB (2998272 bytes)
MD5: 3a78e14c10d9c6bbaa0f82fe9e4f1f9d
Detection count: 340
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\RDB\Registrytasksys.exe
Group: Malware file
Last Updated: June 26, 2020
%LOCALAPPDATA%\Microsoft\winproc32.com File name: winproc32.com
Size: 35.14 MB (35147264 bytes)
MD5: 023a28c0c299c717a353d7a90b088dfa
Detection count: 269
File type: Command, executable file
Mime Type: unknown/com
Path: %LOCALAPPDATA%\Microsoft
Group: Malware file
Last Updated: December 27, 2021
%PROGRAMFILES(x86)%\svhosts\svhosts.exe File name: svhosts.exe
Size: 1.03 MB (1034752 bytes)
MD5: e4b3aea8d33392e62074c28cfa612864
Detection count: 166
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\svhosts
Group: Malware file
Last Updated: March 3, 2017
%PROGRAMFILES%\svhosts\svhosts.exe File name: svhosts.exe
Size: 1.03 MB (1035264 bytes)
MD5: 0f1e731c5b05f10ee8ff0bf7c0abd93a
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\svhosts
Group: Malware file
Last Updated: March 3, 2017
%USERPROFILE%\Pictures\hоst.exe File name: hоst.exe
Size: 16.89 KB (16896 bytes)
MD5: 6d7a5094f62d6959c67b4f75925290fa
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Pictures
Group: Malware file
Last Updated: September 21, 2017
%TEMP%\Realtek Audio\service.exe File name: service.exe
Size: 109.06 KB (109060 bytes)
MD5: 69657822c48d3cd15513e8a5ba364f21
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Realtek Audio
Group: Malware file
Last Updated: March 25, 2017
%ALLUSERSPROFILE%\Application\ApplicationService.exe File name: ApplicationService.exe
Size: 50.68 KB (50688 bytes)
MD5: c28a392936ddc5fe8a2b54258e8d9334
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application
Group: Malware file
Last Updated: March 30, 2016
%APPDATA%\QSound\lcass.exe File name: lcass.exe
Size: 297.98 KB (297984 bytes)
MD5: 1e0321b04b5f23034f1e26f7f13aca7a
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\QSound
Group: Malware file
Last Updated: June 27, 2017
%ALLUSERSPROFILE%\Application\ApplicationService.exe File name: ApplicationService.exe
Size: 77.82 KB (77824 bytes)
MD5: ad536d13a4a7516ee621590680e2802c
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application
Group: Malware file
Last Updated: March 30, 2016
%TEMP%\Realtek Audio\service.exe File name: service.exe
Size: 311.29 KB (311296 bytes)
MD5: 853246fa641564a889c6b4a320ecac6c
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Realtek Audio
Group: Malware file
Last Updated: March 25, 2017
%APPDATA%\QSound\lcass.exe File name: lcass.exe
Size: 297.47 KB (297472 bytes)
MD5: f7ad7589e0c548bbb2ffcb9b7bf7d2ec
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\QSound
Group: Malware file
Last Updated: June 27, 2017
%TEMP%\Realtek Audio\service.exe File name: service.exe
Size: 109.06 KB (109060 bytes)
MD5: 2890aca5d8222b516717d9adb64d2f24
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Realtek Audio
Group: Malware file
Last Updated: March 25, 2017
%APPDATA%\DCleaner\dcc.exe File name: dcc.exe
Size: 5.03 MB (5032448 bytes)
MD5: 656f4950afd11aaced8a0b5176664da5
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\DCleaner
Group: Malware file
Last Updated: July 14, 2017
%APPDATA%\DCleaner\dcc.exe File name: dcc.exe
Size: 5.02 MB (5029376 bytes)
MD5: 3e45d2a587eaa7289f9d1e465547a010
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\DCleaner
Group: Malware file
Last Updated: July 14, 2017
%TEMP%\Realtek Audio\service.exe File name: service.exe
Size: 89.08 KB (89088 bytes)
MD5: 99efc913cc9e4936c36368083f22623b
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Realtek Audio
Group: Malware file
Last Updated: March 25, 2017
%TEMP%\Realtek Audio\service.exe File name: service.exe
Size: 237.56 KB (237568 bytes)
MD5: 7266c1d47ecde3d31d9caa9f51fdb653
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Realtek Audio
Group: Malware file
Last Updated: March 25, 2017
%ALLUSERSPROFILE%\Application\ApplicationService.exe File name: ApplicationService.exe
Size: 84.47 KB (84476 bytes)
MD5: ac5a7bea155f704846ef3378a1d1ca3c
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application
Group: Malware file
Last Updated: March 30, 2016
%USERPROFILE%\Pictures\hоst.exe File name: hоst.exe
Size: 871.93 KB (871936 bytes)
MD5: 0559db41dcc6fdd387188a06adbdf879
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Pictures
Group: Malware file
Last Updated: September 21, 2017
%TEMP%\Realtek Audio\service.exe File name: service.exe
Size: 237.56 KB (237568 bytes)
MD5: f9f53967c10551153a0560b969e9cc75
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Realtek Audio
Group: Malware file
Last Updated: March 25, 2017
%USERPROFILE%\Mis documentos\Mis im?genes\hоst.exe File name: hоst.exe
Size: 46.08 KB (46080 bytes)
MD5: 001d1643d0ec227df1a732003a654986
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Mis documentos\Mis im?genes
Group: Malware file
Last Updated: September 21, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\AudioClient.exe%APPDATA%\DCleaner\dcc.exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\winupsvccfg.exe%APPDATA%\XWinCore\wincore.exe%APPDATA%\ZWinReg\winreg.exe%HOMEDRIVE%\Config.Msi\5ce97.rbf.exe%TEMP%\Realtek Audio\service.exe%WINDIR%\windowsmp.exe

Additional Information

The following directories were created:
%APPDATA%\XWinDat%APPDATA%\mxmetamux

Related Posts

Loading...