Trojan

About “Trojan.MauvaiseRI.S5242494” infection

Malware Removal

The Trojan.MauvaiseRI.S5242494 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MauvaiseRI.S5242494 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs an hook procedure to monitor for mouse events
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: KnightOnline.exe
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key

How to determine Trojan.MauvaiseRI.S5242494?


File Info:

name: EFB3B9523250C1BAAEE1.mlw
path: /opt/CAPEv2/storage/binaries/00216c5b85e27236c7be6bd478225caae61a86a3f573de43410125900f28241c
crc32: E0A4525D
md5: efb3b9523250c1baaee154bf0778f569
sha1: d2ceeb249b2b1fa79ee6fa16243c34b08a628ebd
sha256: 00216c5b85e27236c7be6bd478225caae61a86a3f573de43410125900f28241c
sha512: 8f940e95be59a49875d317063ec8d061304fde03a13255cdb7acb9329eaf904d29d3c944cb012e3523098b8666245849ced6a0a78f78bbb840444d72dcf53c92
ssdeep: 196608:sC7sIqV8OFqyHlvxJAz1IeK0CQywzlDL5wD3V/q:sCgZV+021IV0C7uV2C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA863303961F5E12D8B7CA3F5063FEB85D9ABE1238043B4EE922541094DD81BBB179E7
sha3_384: f0d6ecd467f874f2f5d8f71168b7700b3e76fc01d000c7e5c9b248d910d3d863d20f3a948f1c26d9ed7bd64fe36aaac6
ep_bytes: 60be007047008dbe00a0f8ff57eb0b90
timestamp: 2011-12-23 10:59:31

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 0
CompiledScript: AutoIt v3 Script: 3, 3, 8, 0
Translation: 0x0809 0x04b0

Trojan.MauvaiseRI.S5242494 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.5406952
FireEyeTrojan.GenericKD.5406952
CAT-QuickHealTrojan.MauvaiseRI.S5242494
McAfeeArtemis!EFB3B9523250
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0055e39b1 )
K7AntiVirusTrojan ( 0055e39b1 )
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Ramnit-9161573-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.5406952
NANO-AntivirusTrojan.Win32.Agent.enmxpx
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.5406952
ComodoMalware@#3byfk2ya81rl5
DrWebTrojan.Siggen.400
TrendMicroTROJ_GEN.R002C0RE722
McAfee-GW-EditionBehavesLike.Win32.Injector.wc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.5406952 (B)
GDataTrojan.GenericKD.5406952 (3x)
AviraHEUR/AGEN.1201732
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.C112737
BitDefenderThetaGen:NN.ZedlaF.34742.wz4aa8STwDp
ALYacTrojan.GenericKD.5406952
MAXmalware (ai score=87)
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002C0RE722
RisingMalware.Heuristic!ET#88% (CLOUD)
YandexTrojan.Igent.bVCC3Y.16
IkarusTrojan-Spy.Win32.Agent
MaxSecureTrojan.Autoit.AZA
FortinetW32/Agent.BTHP!tr
AVGWin32:Malware-gen
Cybereasonmalicious.23250c

How to remove Trojan.MauvaiseRI.S5242494?

Trojan.MauvaiseRI.S5242494 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment