Trojan

Trojan.MauvaiseRI.S5256271 removal guide

Malware Removal

The Trojan.MauvaiseRI.S5256271 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MauvaiseRI.S5256271 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Trojan.MauvaiseRI.S5256271?


File Info:

name: 227885A83404B5C27360.mlw
path: /opt/CAPEv2/storage/binaries/1a5a3af2dec43c6c883a4d66d37bf0cb972c5a7de4104822313b6716a20f9dca
crc32: 9E6E18C6
md5: 227885a83404b5c2736032caed791d1c
sha1: 084d48354834061d593af349013aef2f8dde5e73
sha256: 1a5a3af2dec43c6c883a4d66d37bf0cb972c5a7de4104822313b6716a20f9dca
sha512: 42ac975cb9fa3550a382553852dff8bd6620c1c7c1060f8a8d629f8784e69d9b09360aa259c4b058509ea19e9348151c886fb2474812b5d6a80b1fcc059729cc
ssdeep: 49152:suwPRL83bxV+etpDCpHCRQrFh1BbQdJNXt66w11vkKRzpGcLzjItboDau:NB3bxken8HfBbQdPdc1F/G6zjItboDau
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADE5337DA6E5E1C1DA3854F055856BB70543CF93B682702B2B3CFCAB1C376A170A5386
sha3_384: f1f94a87810ce55fc97be73fae61efe180d3a6e209513069d7ee9deb0650b5f94847de63c831de19bc4192297f63fe70
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:23

Version Info:

CompanyName: 企达软件
FileDescription: 疯狂IE安装程序
FileVersion: 1.0.811.501
LegalCopyright: 版权所有(C) 2014 企达软件 保留所有权利
ProductName: 疯狂IE
ProductVersion: 1.0.811.501
Translation: 0x0804 0x03a8

Trojan.MauvaiseRI.S5256271 also known as:

LionicTrojan.Multi.Generic.4!c
CAT-QuickHealTrojan.MauvaiseRI.S5256271
McAfeeArtemis!227885A83404
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforRiskware.Win32.FlyStudio.C
K7AntiVirusTrojan ( 005194cc1 )
K7GWTrojan ( 005194cc1 )
CyrenW32/Trojan.GMK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Tool.Qqhack-9919543-0
NANO-AntivirusRiskware.Win32.FlyStudio.fcgfoz
AvastWin32:Malware-gen
SophosGeneric PUA AI (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionGenericRXMB-KX!BD01AEA6D5BB
IkarusTrojan-Clicker.Win32.Flyst
Antiy-AVLTrojan/Generic.ASCommon.FB
KingsoftWin32.Troj.Generic_a.c.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Application.FlyStudio.Y (4x)
MAXmalware (ai score=100)
VBA32TrojanPSW.Banker
MalwarebytesTrojan.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H06GN21
RisingTrojan.Win32.Generic.180CE864 (C64:YzY0Oki92axl+sQ3)
FortinetW32/FlyStudio.C!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.MauvaiseRI.S5256271?

Trojan.MauvaiseRI.S5256271 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment