ForestTiger is a sophisticated Windows-based malware threat that security researchers have tracked under multiple names, including ScoringMathTea. This malicious software targets Windows systems through Windows PE executables and has been actively monitored since its emergence in the threat landscape. While not as widely publicized as some ransomware families, ForestTiger represents a serious risk to both home users and small businesses, capable of compromising system security and potentially opening backdoors for additional payloads.

ForestTiger — cybersecurity illustration
Photo by John (Giannis) Tekeridis on Pexels

What makes ForestTiger particularly concerning is its stealthy operational profile—designed to evade detection while establishing persistence on infected machines. Understanding how this threat operates and what signs to look for can mean the difference between a quick cleanup and a complete system compromise.

Think you're infected right now? Disconnect your computer from the internet immediately by unplugging the ethernet cable or disabling Wi-Fi. Do not attempt to access sensitive accounts or financial information. Call us at (770) 299-3550 or bring your machine to our Roswell shop at 1255 Hembree Road. We can diagnose and remove ForestTiger infections same-day in most cases.

Threat Profile

Threat Name ForestTiger
Known Aliases ScoringMathTea
Threat Type Trojan / Backdoor (typical for this family)
Target Platform Windows (all recent versions)
File Format Windows PE executable (.exe)
First Observed Prior to September 2026
Distribution Method Phishing emails, malicious downloads, software bundling
Persistence Mechanism Registry modifications, scheduled tasks (typical for this family)
Primary Payload Backdoor access, potential data exfiltration
Detection Difficulty Moderate to High
Removal Complexity Moderate—requires registry cleanup and file removal
Reinfection Risk Medium (if initial infection vector not addressed)

How It Spreads

ForestTiger primarily infiltrates systems through social engineering tactics and compromised downloads. Like many modern malware families, it relies on tricking users into executing malicious files rather than exploiting unpatched vulnerabilities. The threat actors behind ForestTiger understand that the human element remains the weakest link in cybersecurity, and they've crafted distribution methods accordingly.

The most common infection scenarios we see at our Roswell shop involve users who thought they were downloading legitimate software or opening what appeared to be important documents. Once the executable runs, ForestTiger begins its installation process silently in the background while the user may see nothing more than an error message or a brief loading screen.

Common distribution vectors include:

  • Phishing email attachments disguised as invoices, shipping notifications, or tax documents with executable files renamed to look like PDFs or Word documents
  • Fake software updates for popular programs like Adobe Flash, Java, or media codecs that prompt downloads from unofficial websites
  • Pirated software bundles where ForestTiger is packaged alongside cracked applications or key generators
  • Malicious advertisements (malvertising) on compromised websites that trigger drive-by downloads when clicked
  • Infected USB drives that auto-execute when plugged into a Windows PC with AutoRun enabled
  • Compromised websites hosting trojanized downloads that appear legitimate but contain ForestTiger payloads

What It Does On Your Machine

Once ForestTiger executes on your system, it immediately begins establishing persistence—ensuring it survives reboots and continues operating even after you think you've closed the program. Based on sandbox analysis and behavioral patterns typical of this malware family, ForestTiger modifies Windows registry keys to auto-start with your system and may create scheduled tasks to re-launch itself at specific intervals.

The malware typically operates with elevated privileges whenever possible, attempting to bypass User Account Control (UAC) prompts through known techniques. Once established, ForestTiger can serve as a backdoor for threat actors to remotely access your machine, download additional malware payloads, or exfiltrate sensitive data. This modular approach means the initial infection may be just the beginning—ForestTiger can act as a gateway for ransomware, spyware, or cryptominers depending on the attacker's objectives.

Performance degradation is often the first symptom users notice. Your computer may run slower than normal, experience unexplained network activity, or show unusual CPU usage when supposedly idle. These symptoms occur because ForestTiger is communicating with command-and-control servers, scanning your file system, or performing other malicious activities in the background.

# Typical ForestTiger system artifacts (observed in sandbox environments): # Executable locations (varies by variant): C:\Users\[Username]\AppData\Local\Temp\[random].exe C:\Users\[Username]\AppData\Roaming\[random_folder]\service.exe C:\ProgramData\[legitimate-sounding_name]\ # Registry persistence keys (common locations): HKCU\Software\Microsoft\Windows\CurrentVersion\Run HKLM\Software\Microsoft\Windows\CurrentVersion\Run HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce # Network behavior: Outbound connections to unknown IP addresses DNS queries to suspicious domains (varies by campaign) Encrypted traffic on non-standard ports

Manual Removal — Step by Step

01

Disconnect from the Internet

Immediately disconnect your computer from all networks—unplug the ethernet cable and disable Wi-Fi. This prevents ForestTiger from receiving commands, downloading additional payloads, or exfiltrating your data while you work on removal.

02

Boot into Safe Mode with Networking

Restart your computer and repeatedly press F8 (or Shift+F8 on newer systems) during boot. Select "Safe Mode with Networking" from the menu. This loads Windows with minimal drivers and prevents most malware from auto-starting, giving you a cleaner environment for removal work.

03

Run a Full System Scan with Updated Antivirus

Update your antivirus definitions (you'll need to temporarily reconnect to the internet in Safe Mode), then run a complete system scan. Let it quarantine or remove anything it identifies. Quality tools like Malwarebytes, ESET, or Kaspersky have detection signatures for ForestTiger and its known variants.

04

Check Startup Programs and Services

Press Windows+R, type msconfig, and hit Enter. Go to the Startup tab and look for unfamiliar entries, especially those with random names or located in Temp or AppData folders. Disable anything suspicious. Also check the Services tab for unknown services set to automatic startup.

05

Manually Inspect Registry Run Keys

Press Windows+R, type regedit, and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries pointing to executables in unusual locations (AppData, Temp, ProgramData with random folder names). Right-click and delete suspicious entries, but be cautious—deleting legitimate system entries can cause problems.

06

Delete Malicious Files and Folders

Navigate to the file locations identified by your antivirus scan or found in the registry. Common locations include C:\Users\[YourName]\AppData\Local\Temp and C:\Users\[YourName]\AppData\Roaming. Delete the entire folders associated with ForestTiger. You may need to show hidden files (Folder Options > View > Show hidden files).

07

Check Scheduled Tasks

Open Task Scheduler (search for it in the Start menu). Review the Task Scheduler Library for any tasks you didn't create, especially those running executables from suspicious locations or scheduled to run at system startup or user login. Delete any tasks associated with unknown executables.

08

Reset Browser Settings

ForestTiger may have modified your browser to install malicious extensions or change your homepage and search engine. Open each browser you use, go to settings, and reset to defaults. Remove any extensions you didn't install yourself.

09

Run a Secondary Scan with a Different Tool

Different antivirus engines catch different things. Download and run a second-opinion scanner like Malwarebytes (if you haven't already used it), HitmanPro, or Microsoft Safety Scanner. This catches anything your primary antivirus might have missed.

10

Change All Passwords from a Clean Device

After removal is complete, assume that any passwords entered while infected may have been compromised. Use a different, clean computer or smartphone to change passwords for email, banking, social media, and other critical accounts. Enable two-factor authentication wherever available.

Prevention

  1. Keep Windows and all software updated. Enable automatic updates for Windows, and regularly update all installed programs. Many infections exploit known vulnerabilities in outdated software—patches close those security holes before malware can exploit them.
  2. Use reputable antivirus software and keep it current. Free options like Windows Defender offer basic protection, but paid solutions from companies like ESET, Kaspersky, or Bitdefender provide more comprehensive defense. Whatever you choose, ensure it updates daily and runs real-time protection.
  3. Be extremely skeptical of email attachments and links. Never open attachments from unknown senders. Even if an email appears to come from someone you know, verify through a separate communication channel before opening unexpected attachments—email accounts get compromised and used to spread malware to contact lists.
  4. Download software only from official sources. Avoid third-party download sites, torrent repositories, and "free" versions of paid software. These are common distribution points for trojanized installers that bundle malware with legitimate applications.
  5. Disable macros in Office documents by default. Many malware families spread through malicious Word or Excel macros. Configure Microsoft Office to disable macros or at least prompt before enabling them. Never enable macros in documents from unknown sources.
  6. Use a standard user account for daily activities. Don't run your Windows session with administrator privileges for routine browsing and email. Create a standard user account for everyday use—this limits malware's ability to make system-wide changes even if it executes.
  7. Implement regular backups to external storage. Maintain current backups of important files on an external drive that you disconnect when not backing up, or use a reputable cloud backup service. This won't prevent infection, but it ensures you can recover your data if malware strikes.
  8. Enable User Account Control (UAC) and don't click through prompts reflexively. UAC prompts exist to warn you when something tries to make system changes. If you see a UAC prompt when you didn't intentionally install or configure something, click "No" and investigate what triggered it.
Our 90-Day Warranty: When Computer Repair Roswell removes malware from your system, we stand behind our work. If the same infection returns within 90 days through no fault of your own, we'll clean it again at no additional charge. We also provide documentation of what was found and removed, plus specific recommendations to prevent reinfection based on your particular case.

Bring It In

While the manual removal steps above can work for tech-savvy users, ForestTiger removal is tricky business—miss one registry key or scheduled task, and the infection can regenerate itself. We see this frequently: someone follows an online removal guide, thinks they've cleaned their system, then discovers two weeks later the malware is still there, just operating more quietly.

At Computer Repair Roswell, we've developed systematic procedures for malware removal that go beyond what antivirus software alone can accomplish. We use multiple scanning tools, manually verify system integrity, check for secondary infections that may have been downloaded by ForestTiger, and ensure your system is truly clean before we return it to you. Most ForestTiger removals take 2-4 hours of bench time, and we can usually complete the work same-day if you bring your machine in during the morning. Call us at (770) 299-3550 or stop by our shop at 1255 Hembree Road in Roswell. We're here Monday through Friday, 9 AM to 6 PM, and Saturday 10 AM to 4 PM. No appointment necessary—just bring the infected computer and we'll get you taken care of.