Trojan

Trojan.MauvaiseRI.S5252149 removal instruction

Malware Removal

The Trojan.MauvaiseRI.S5252149 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MauvaiseRI.S5252149 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
css.jipinfeiche.cn

How to determine Trojan.MauvaiseRI.S5252149?


File Info:

crc32: 34B841B2
md5: dbd37809cf6dda2d6d3f8995b5743ca5
name: fcshengdoushixingshihuangjinchuanshuowanjiepianzhongwenban.exe
sha1: 48fcc7058db4642a44521d7f7f157f65a2ff9b8f
sha256: 4daad8df53c228b42eb8038a28923afde02eaa64af777ed7afc55ab7761f31eb
sha512: 5ddab9ccf3143dcf53930379949f84daa0b5b5661ab94c971a885cee396f5bdfc3043953ae177be73603f91eb51ae1dccedb59b8b0f9e2d8b638e09f5b1f5d24
ssdeep: 98304:IDUfGjq32QrxyHFjPpqaxO160DzfGjq32V:FVrxyHFTpqNV0
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: (C)
ProductName:
FileVersion:
FileDescription: Producer
Translation: 0x0804 0x03a8

Trojan.MauvaiseRI.S5252149 also known as:

BkavW32.HfsAdware.A41A
MicroWorld-eScanAdware.GenericKD.30935074
FireEyeGeneric.mg.dbd37809cf6dda2d
CAT-QuickHealTrojan.MauvaiseRI.S5252149
Qihoo-360Win32/Trojan.Adware.37e
McAfeeArtemis!DBD37809CF6D
MalwarebytesAdware.Kuaiba
AlibabaAdWare:Win32/Agent.aa7bbfb4
K7GWAdware ( 004b8bbc1 )
K7AntiVirusAdware ( 004b8bbc1 )
TrendMicroTROJ_SPNR.15AE15
BaiduMulti.Threats.InArchive
NANO-AntivirusRiskware.Win32.Kuaiba.ebxjry
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Ramnit-5500
GDataAdware.GenericKD.30935074
Kasperskynot-a-virus:AdWare.Win32.Agent.jkzp
BitDefenderAdware.GenericKD.30935074
AvastWin32:PUP-gen [PUP]
Ad-AwareAdware.GenericKD.30935074
EmsisoftAdware.GenericKD.30935074 (B)
ComodoApplication.Win32.Kuaiba.BC@5np13a
F-SecureAdware.ADWARE/Adware.Gen7
DrWebTrojan.DownLoader12.10274
ZillyaAdware.KuaibaCRTD.Win32.183
Invinceaheuristic
McAfee-GW-EditionPUP-XBL-MX
SophosGeneric PUA NP (PUA)
WebrootW32.Adware.Gen
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Win32.BTSGeneric
ArcabitAdware.Generic.D1D80822
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.jkzp
MicrosoftPUA:Win32/Kuaiba
AhnLab-V3Adware/Win32.Kuaiba.C930936
ALYacAdware.GenericKD.30935074
MAXmalware (ai score=100)
VBA32Trojan.Downloader
ESET-NOD32Win32/Adware.Kuaiba.H
TrendMicro-HouseCallTROJ_SPNR.15AE15
TencentWin32.Trojan.Falsesign.Wvkl
IkarusPUA.Kuaiba
eGambitGeneric.Adware
FortinetRiskware/Moat.CED4C7BB
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.9cf6dd
PandaTrj/CI.A
MaxSecureTrojan.Malware.8829647.susgen

How to remove Trojan.MauvaiseRI.S5252149?

Trojan.MauvaiseRI.S5252149 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment