Trojan

Trojan.MauvaiseRI.S5257626 information

Malware Removal

The Trojan.MauvaiseRI.S5257626 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MauvaiseRI.S5257626 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to modify proxy settings

Related domains:

www.12345ee.com

How to determine Trojan.MauvaiseRI.S5257626?


File Info:

crc32: F749C66A
md5: c402bd0459a0f5baa938c01aceea080c
name: C402BD0459A0F5BAA938C01ACEEA080C.mlw
sha1: 19a04fb6859368a64455a6520e324d607ecb3994
sha256: 1a2c88315ecdd677333b459b54028a2281bbc64c1b3ce8ab24d27ce40b11fff2
sha512: d1486cb65f9b41c2047eb255596aa54b8173a5f3278f21462f120ecf7634b7500eb29237647a3ec128b081fb92bc966092096a186a6ffd1268f33cde7844fda2
ssdeep: 49152:Ne9NSWggiPDZrNTgcRdi6VgnhXj+s8KuqGaX0ToIBAUZLYtBb:0XSZBPdNvREhoJBAUZLQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709xff1awww.12345aa.com
FileVersion: 3.7.0.0
CompanyName: www.12345aa.com
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x529bx738bQQx7fa4x53d1x5668
ProductVersion: 3.7.0.0
FileDescription: x529bx738bQQx7fa4x53d1x5668
Translation: 0x0804 0x04b0

Trojan.MauvaiseRI.S5257626 also known as:

K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Multi.Generic.lwj0
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5257626
CylanceUnsafe
ZillyaTool.IMEStartup.Win32.961
SangforRiskTool.Win32.IMEStartup.gen
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.685936
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-9820446-0
Kasperskynot-a-virus:VHO:RiskTool.Win32.IMEStartup.gen
NANO-AntivirusTrojan.Win32.Advload.fabxcs
TencentWin32.Trojan.Qqpsw.Auto
SophosGeneric PUA BJ (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.c402bd0459a0f5ba
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftPUA:Win32/Vigua.A
GDataWin32.Application.PUPStudio.A
AhnLab-V3PUP/RL.Generic.R242480
McAfeeArtemis!C402BD0459A0
MAXmalware (ai score=96)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H0CEO21
RisingStealer.QQpass!1.648F (CLASSIC)
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.ELG!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.MauvaiseRI.S5257626?

Trojan.MauvaiseRI.S5257626 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment