No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

ScarH, worm, return, the, vandals
Juniper Networks has extended its SSL VPN security to the iPad with the release...
A recent survey by security company Sophos exposes the dilemma to business posed by...
You might think that thousands, nay millions of people will be on the Internet...
- Sponsored Editorial - AppLabs sees huge value proposition for its clients with...
- sponsored editorial - Australian independent software testing and training organisation, Planit,...

Scar-H worm: return of the IT vandals

Business IT - Security

Do you remember being told that malware developers have turned their attention to making money? It seems the vandals are still around.


Sophos is warning of a Windows worm it has labelled Scar-H. The payload of this nasty piece of malware methodically replaces every .exe file on the C: drive with a copy of itself, retaining the original filenames.

Since the process starts with the system directory, things quickly go bad. Once Drwtsn32.exe has been replaced by Scar-H, it gets called recursively, resulting in a freeze.

And then trying to reboot the system fails, as critical system files have been replaced.

The worm spreads by installing AutoRun files on devices mapped to drive letters.

Cleaning up involves removing all the copies of Scar-H and its associated registry entries, and replacing the real files from a backup or by reinstalling the relevant software.