Trojan

Trojan.GenericRI.S18686101 removal instruction

Malware Removal

The Trojan.GenericRI.S18686101 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericRI.S18686101 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing

How to determine Trojan.GenericRI.S18686101?


File Info:

name: EAA7D7A9FCB685A0C2D5.mlw
path: /opt/CAPEv2/storage/binaries/4bc78abf96e0777755b6ccf21a6d1a4e3f53ff96eb1d169727886b897c64d416
crc32: 8CF62014
md5: eaa7d7a9fcb685a0c2d5b87b1480bb9a
sha1: a2efad9ebe7ac1c9fe775c78f93d0def9dc36def
sha256: 4bc78abf96e0777755b6ccf21a6d1a4e3f53ff96eb1d169727886b897c64d416
sha512: e55aabcf67821ecfb99d8f893408cf5e80df48c48ab4a34c79a4fe110ba9d977095b1505a77177c494762d08011cb79b3cefe0bf26d36533a1bed9e6e42de839
ssdeep: 49152:jOLPWqaUqcHQNC/MetJsuempqX2VV07Nr1OPsxTeQTQ88yk:jOLPWqrqcwNMMEJXNq57Nr1W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AA5CF22FB81C572F5D2017962BA577F4C3AAA304329C4E3D79129689D302E17B3E7D6
sha3_384: 03c276ab4b9568d9d64bd66f49c0cdcde2f9c8818c4ba36e84f70734b36b53ec2b07ffdd6c65951cf09b534b9206e4fe
ep_bytes: e82b060000e98efeffff558bec56ff75
timestamp: 2021-01-29 03:47:33

Version Info:

CompanyName: 北京布丁跳跳科技有限公司
FileDescription: 智能云五笔输入法
InternalName: 智能云五笔输入法
LegalCopyright: Copyright (C) 2020
OriginalFilename: SWWordMgr.exe
ProductName: 智能云五笔输入法
ProductVersion: 1.6.3.10128
Translation: 0x0804 0x04b0

Trojan.GenericRI.S18686101 also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.Burden.2!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.eaa7d7a9fcb685a0
CAT-QuickHealTrojan.GenericRI.S18686101
CylanceUnsafe
ZillyaAdware.Burden.Win32.2305
SangforVirus_Suspicious.Win32.Sality.bh
AlibabaAdWare:Win32/Softcnapp.f44ea7df
K7GWAdware ( 00571de41 )
K7AntiVirusAdware ( 00571de41 )
BitDefenderThetaGen:NN.ZexaF.34114.cE2@aS!nsChj
VirITWin32.Sality.BI
CyrenW32/Sality.AY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.BH potentially unwanted
TrendMicro-HouseCallPE_SALITY.ER
Paloaltogeneric.ml
Kasperskynot-a-virus:UDS:AdWare.Win32.Burden.gen
NANO-AntivirusRiskware.Win32.Burden.ikibkx
AvastWin32:Sality [Inf]
TencentPua:Adware.Win32.Burden.16000021
VIPREVirus.Win32.Sality.atbh (v)
TrendMicroPE_SALITY.ER
McAfee-GW-EditionBehavesLike.Win32.Sality.vh
SophosGeneric PUA KC (PUA)
IkarusPUA.Softcnapp
JiangminAdWare.Burden.aqx
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34CA2DF
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotAdware.Burden.2131296
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R424864
Acronissuspicious
VBA32Adware.Burden
MalwarebytesPUP.Optional.Softcnapp
APEXMalicious
RisingAdware.Agent!1.C1A1 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureAdware.notavirus.WIN32.AdWare.Burden.gen_211742
FortinetAdware/Softcnapp.BF
AVGWin32:Sality [Inf]

How to remove Trojan.GenericRI.S18686101?

Trojan.GenericRI.S18686101 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment