Trojan

Should I remove “Trojan.MauvaiseRI.S5256069”?

Malware Removal

The Trojan.MauvaiseRI.S5256069 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MauvaiseRI.S5256069 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan.MauvaiseRI.S5256069?


File Info:

name: 7DCC479B94CD8300AEE8.mlw
path: /opt/CAPEv2/storage/binaries/4ae04d8272912945e5a9d4191053b4caaba61c671bd90f2d090d4ca2acb8d17f
crc32: E9A5C43B
md5: 7dcc479b94cd8300aee8965b8adc9e59
sha1: 22482b330733cd0e9553c1e3b15ad3d5c9e7a4a1
sha256: 4ae04d8272912945e5a9d4191053b4caaba61c671bd90f2d090d4ca2acb8d17f
sha512: b06880d887b20923b753c8c21ed2eef9929c3c3cd9b63d08e6b1c4d19f32580762de9f5f1cfff72c0d7b7db38ada7ab9fb8d951b092bb3acf87bb7e3961c44e1
ssdeep: 49152:nkxjNniVQ2/Cin+0MMV5bS7NwaHjkYyHM9gZPoKoOyc:iNni7/Cm3naHjgpF
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T18E85AE55E76405F4D67BC238C852958BE7F1B81517B08BEF0AA60AAA0F337D05E3EB11
sha3_384: a5054522e3fb5cd7d9adb51b4c4ac0d1a1288a46fb0e777d2e3fda5bf07b516f5ddb5fd477e8b64f1240e069ffdea011
ep_bytes: 4883ec28e8770700004883c428e982fe
timestamp: 2017-12-09 17:54:17

Version Info:

0: [No Data]

Trojan.MauvaiseRI.S5256069 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.980121
FireEyeGeneric.mg.7dcc479b94cd8300
CAT-QuickHealTrojan.MauvaiseRI.S5256069
ALYacGen:Variant.Razy.980121
ZillyaWorm.Agent.Win64.39
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052036a1 )
K7GWTrojan ( 0052036a1 )
Cybereasonmalicious.b94cd8
CyrenW64/CoinMiner.FI.gen!Eldorado
ESET-NOD32a variant of Win64/Agent.C
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.980121
AvastWin64:Malware-gen
TencentMalware.Win32.Gencirc.10ba846a
Ad-AwareGen:Variant.Razy.980121
EmsisoftGen:Variant.Razy.980121 (B)
SophosMal/Miner-Y
IkarusPUA.CoinMiner
GDataGen:Variant.Razy.980121
JiangminTrojanDropper.Agent.cifi
Antiy-AVLTrojan/Generic.ASMalwS.237C563
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.R361436
MAXmalware (ai score=84)
MalwarebytesMalware.AI.3510694035
YandexTrojan.GenAsa!qpIRv3xIaoo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW64/CoinMiner.C!worm
AVGWin64:Malware-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.MauvaiseRI.S5256069?

Trojan.MauvaiseRI.S5256069 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment