Trojan

Trojan.MauvaiseRI.S5256735 (file analysis)

Malware Removal

The Trojan.MauvaiseRI.S5256735 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MauvaiseRI.S5256735 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.MauvaiseRI.S5256735?


File Info:

name: 41D8B04B20565D65D38A.mlw
path: /opt/CAPEv2/storage/binaries/096b80baaff82cbb554d9e979b79c864947e019a83dc16e2cb25b5ec3fcf24f5
crc32: DD38D1C7
md5: 41d8b04b20565d65d38ae7b1a58bfc74
sha1: b06705ce024a767d5f0b2f3a94b565cd46179a93
sha256: 096b80baaff82cbb554d9e979b79c864947e019a83dc16e2cb25b5ec3fcf24f5
sha512: 35bb14544bc50582346d85455f8edc8c5780bcff9b4908a723e25830ae960b1e6e6dc50f7f9c24af1178371a3ec3eee7d4e2159e621b1ab9d296cc772f854d10
ssdeep: 768:O5J7QAhoLGIOnnvz/vY47kD0p3wndfNKCKRaGQ:Ov7ELZObXn7wOAfNKaGQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B25E1437A9C3446C2D799722A5D3E01520BF3056BBA8E8A316DE07E6F35A948D93C2D
sha3_384: dc235d55f3f9ae4955aa6ac9401944c61c8d26b14af89ca88da85b43f9a63bd1d8552ff2dc09de450126c34896791a86
ep_bytes: 60be00d040008dbe0040ffff5783cdff
timestamp: 2007-01-27 04:58:12

Version Info:

Comments:
CompanyName: FlyingSnow
FileDescription: ATK 补丁精灵
FileVersion: 3, 1, 0, 0
InternalName: ATK 补丁精灵
LegalCopyright: 版权所有 (C) 2007
LegalTrademarks:
OriginalFilename: ATKSpirit.EXE
PrivateBuild:
ProductName: ATK 补丁精灵
ProductVersion: 3, 1, 0, 0
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan.MauvaiseRI.S5256735 also known as:

BkavW32.AIDetect.malware1
FireEyeGeneric.mg.41d8b04b20565d65
CAT-QuickHealTrojan.MauvaiseRI.S5256735
McAfeeGenericRXAK-FQ!27BA0EC32329
CylanceUnsafe
K7AntiVirusTrojan ( 0057e2ea1 )
K7GWTrojan ( 0057e2ea1 )
CrowdStrikewin/malicious_confidence_70% (D)
VirITTrojan.Win32.Generic.BUMK
CyrenW32/A-6a7a47c8!Eldorado
APEXMalicious
NANO-AntivirusTrojan.Win32.Kryptik.cyqoyk
RisingTrojan.Occamy!8.F1CD (RDMK:cmRtazojGllPF/ao0aqIhDkOQiGj)
ZillyaAdware.BrowseFox.Win32.264742
McAfee-GW-EditionGenericRXAK-FQ!27BA0EC32329
SophosGeneric ML PUA (PUA)
JiangminTrojan/FraudPack.afd
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
YandexTrojan.Agent!wBORs7r4cWo
Cybereasonmalicious.e024a7

How to remove Trojan.MauvaiseRI.S5256735?

Trojan.MauvaiseRI.S5256735 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment