Trojan

What is “Trojan.MauvaiseRI.S5244566”?

Malware Removal

The Trojan.MauvaiseRI.S5244566 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MauvaiseRI.S5244566 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings

How to determine Trojan.MauvaiseRI.S5244566?


File Info:

name: FA05439753DB55D65400.mlw
path: /opt/CAPEv2/storage/binaries/69ce61c99b821c882af2c8fa6541891cc6685f80c888e84b850d8f60a943956a
crc32: 059041C8
md5: fa05439753db55d65400dabe45a7aa4d
sha1: 0be62a136c6f3868a497e2703f43ecc86eb98e10
sha256: 69ce61c99b821c882af2c8fa6541891cc6685f80c888e84b850d8f60a943956a
sha512: f09d9ea5af8b8c272acf22b7d3dfe9eb3424437e6bd6d8bfc97739d3cc66bf12b9b8b1330220f48206499b6685e222c2368eed2b3126c6d6bf9c87436308a50b
ssdeep: 6144:tbSxbSankP+6bwnkP+6bwnkP+6bwnkP+6bfl0SyhnkP+6bd:BeQ+m+m+m+IlbyC+0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E340277630A5617E609BC7BF37E53A0186E56A06EC7C4E0E65DF7E781B2C25018AB08
sha3_384: 460f991f12a9c3c60274a0f0cc4f0ef9fdda661d59da274337550e678aee666bcaa448796f5384868db685e6605ebd88
ep_bytes: 60be002042008dbe00f0fdff5783cdff
timestamp: 2008-03-14 10:18:02

Version Info:

0: [No Data]

Trojan.MauvaiseRI.S5244566 also known as:

LionicWorm.Win32.Socks.lfqa
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Crypt.AI
FireEyeGeneric.mg.fa05439753db55d6
CAT-QuickHealTrojan.MauvaiseRI.S5244566
ALYacTrojan.Crypt.AI
CylanceUnsafe
VIPRETrojan.Crypt.AI
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004ac0a31 )
K7GWTrojan ( 004ac0a31 )
Cybereasonmalicious.753db5
BitDefenderThetaAI:Packer.631E28991B
VirITTrojan.Win32.Agent.BME
CyrenW32/Socks.A.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Socks.NAL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Worm.Socks-7102088-0
KasperskyWorm.Win32.Socks.pgf
BitDefenderTrojan.Crypt.AI
NANO-AntivirusTrojan.Win32.Pace.ihwkc
AvastWin32:Injecter-AT [Trj]
TencentWorm.Win32.Socks.za
Ad-AwareTrojan.Crypt.AI
SophosML/PE-A + Troj/Agent-THB
ComodoWorm.Win32.Agent.~CY@2v635
DrWebTrojan.DownLoader.56001
ZillyaWorm.Socks.Win32.830
TrendMicroWORM_SOCKS.BL
McAfee-GW-EditionBehavesLike.Win32.Ctsinf.dc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Crypt.AI (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.162YZAI
JiangminWorm/AutoRun.gxl
GoogleDetected
AviraTR/PSW.Agent.nhg
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.1EB
ViRobotWorm.Win32.Socks.39785
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Socks.R2896
McAfeegeneric!bg.f
VBA32BScope.TrojanDownloader.Small
MalwarebytesGeneric.Worm.Autorun.DDS
TrendMicro-HouseCallWORM_SOCKS.BL
RisingTrojan.Agent!1.6618 (CLOUD)
YandexTrojan.GenAsa!Yuu3lqrxeJg
IkarusTrojan-Downloader.Win32.Small
FortinetW32/SOCKS.BP!worm
AVGWin32:Injecter-AT [Trj]
PandaTrj/Downloader.TCG
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.MauvaiseRI.S5244566?

Trojan.MauvaiseRI.S5244566 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment