Trojan

Trojan.Mauvaise.S330271 (file analysis)

Malware Removal

The Trojan.Mauvaise.S330271 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Mauvaise.S330271 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempted to write directly to a physical drive
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan.Mauvaise.S330271?


File Info:

name: 39B2BC3F33D895CB2D4C.mlw
path: /opt/CAPEv2/storage/binaries/02237fddfa265babe9bb805b9e2f3e8427c0f9a5cd34df1172286a1a1677f2f6
crc32: 742EB481
md5: 39b2bc3f33d895cb2d4c0d4de0b94f74
sha1: 3d0e2150fbd544bf6d1e8c3f9e3977a278ff1530
sha256: 02237fddfa265babe9bb805b9e2f3e8427c0f9a5cd34df1172286a1a1677f2f6
sha512: 1b78f56a0d05c84836d79072616437773e1f2e45d52101c2b159465e37d83b3a1351ed5b77f4482c21a62e6cc226688fbff3b2da7e7859b76ac97313b428dd77
ssdeep: 98304:OqxUxRlLRjWc6I+YWhM1MDqy6aNckOnkeRas6wjPlutZYiUHEteRqI+hNSvZWgUC:O/ViE+YX1Mrck+kGdjPwt2iyEctBRNL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E5623327282D132D8B118F19DBDAA9E293EB825072A01E773DC1B3D1DA50D35E35B5B
sha3_384: 716dde3af78804ad859c7c25bd432bd4f77c6e8f1e5fc7485c9b31fc20d2c980f58dec93de613f17b7baf4bf42520117
ep_bytes: e8c2b70000e989feffff8bff558bec51
timestamp: 2013-10-01 21:33:33

Version Info:

FileDescription: Application 32 bit
FileVersion: 2.2.6.2
InternalName: Application
OriginalFilename: Application
ProductVersion: 2.2.6.2
Translation: 0x0409 0x04b0

Trojan.Mauvaise.S330271 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Dapato.b!c
CAT-QuickHealTrojan.Mauvaise.S330271
CylanceUnsafe
SangforTrojan.Win32.Dapato.8
Cybereasonmalicious.f33d89
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Dapato.dooyof
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10bb8149
ZillyaDropper.Dapato.Win32.19213
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Dapato.och
WebrootW32.Dapato.Dfqu
KingsoftWin32.Troj.Dapato.ev.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Dapato.R103239
McAfeeGenericRXAA-AA!39B2BC3F33D8
VBA32TrojanDropper.Dapato
RisingDropper.Dapato!8.2A2 (CLOUD)
YandexTrojan.DR.Dapato!J6wld5QKOU0
IkarusTrojan-Dropper.Win32.Dapato
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dapato.DFQU!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Mauvaise.S330271?

Trojan.Mauvaise.S330271 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment