Trojan

What is “Trojan.Mauvaise.S1273039”?

Malware Removal

The Trojan.Mauvaise.S1273039 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Mauvaise.S1273039 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Mauvaise.S1273039?


File Info:

name: 42582805E4215C1FF41D.mlw
path: /opt/CAPEv2/storage/binaries/4f9f2c3c537cfc15757cffa76863870a601075b12486090ebe4859eaf3147416
crc32: C1045D85
md5: 42582805e4215c1ff41d8951e521d51e
sha1: e32172a065376b4626b9ca0b0a60dd4f164567c7
sha256: 4f9f2c3c537cfc15757cffa76863870a601075b12486090ebe4859eaf3147416
sha512: 62a28d2db056c30859922ac4b3fe6ffdda00212fa10189ba1844726e5edefc924702f783ed4076ac03a70505e48d0c572df86067a02e15f63a55700765fcb8c1
ssdeep: 1536:oSIIHlKMQNe803YpTIkLX4KJy8x/ytrq70UV:opIENl07ubmO7x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B943F1E1E36F0C17F147817667A3190BB2BFA2690B1D1B27128C6D4DABF13D24F65868
sha3_384: ddde2965cab806a70df4b98659cef9740505a46599909d59236f08a1ee43e05e1e009d2e4e059a172db581772810be36
ep_bytes: 60e80000000083cdff31db5e8dbefaff
timestamp: 2005-09-11 13:02:22

Version Info:

CompanyName: Desperate Soft. Group
FileVersion: 2.0.0
FileDescription: Offset Patch Maker
LegalCopyright: WaRRioRCRAFT
LegalTrademarks: warriorcraft@operamail.com
OriginalFilename: Ne Orjinali Manyak
ProductName: Turkler Internette!
ProductVersion: 1.0.0
Translation: 0x0409 0x04b0

Trojan.Mauvaise.S1273039 also known as:

LionicRiskware.Win32.Generic.1!c
FireEyeGeneric.mg.42582805e4215c1f
CAT-QuickHealTrojan.Mauvaise.S1273039
SangforPUP.Win32.Presenoker.mt
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/HackTool.Patcher.A potentially unsafe
APEXMalicious
Paloaltogeneric.ml
McAfee-GW-EditionBehavesLike.Win32.Trojan.qc
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
MicrosoftPUA:Win32/Presenoker
CynetMalicious (score: 100)
McAfeeArtemis!42582805E421
VBA32BScope.Trojan.Wacatac
RisingPUA.Keygen!8.3EB (CLOUD)
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Mauvaise.S1273039?

Trojan.Mauvaise.S1273039 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment