Trojan

About “Trojan.MauvaiseRI.S5257721” infection

Malware Removal

The Trojan.MauvaiseRI.S5257721 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MauvaiseRI.S5257721 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Trojan.MauvaiseRI.S5257721?


File Info:

name: 3ECA8F37D90AECA37F6E.mlw
path: /opt/CAPEv2/storage/binaries/1aad3f11c475371c0f37966125d28c6383b254c7fb3abfe235df248941bf6b88
crc32: 4464B703
md5: 3eca8f37d90aeca37f6e9ccb78a58574
sha1: 09b702f68f4d255e2b0277c7c40e4afe02209bb6
sha256: 1aad3f11c475371c0f37966125d28c6383b254c7fb3abfe235df248941bf6b88
sha512: 141f66f626e64860149ebe3c97bbff6ce59ef14c092c81426257870ddd0639185bf9a7589ca1d7a2ad24bde29e3ef4ee7867f021e4116f633768d8d703e2ea4b
ssdeep: 24576:kJACjAGyiVjYUm5F3lhVSOqyANoNYdoMlG4c4RTINjpHB1T3pFtbbUqOkNS:kCCDm5dlh6FyMlG4JGFhNZFtPUuS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E485AE13A65281A1D660347216BB133CEA75E3B60D318A97D7F5CCB42D30662E377F8A
sha3_384: df8bebfaa99368376c45b1f19b15e6acaee82a59a9e80cc0dbefa2fc4cb3810930a7002bb66f5a11a851f0655424f830
ep_bytes: 558bec6aff68588f580068f4c04b0064
timestamp: 2014-12-17 03:14:11

Version Info:

FileVersion: 4.6.0.0
FileDescription: 九天科技-投票软件
ProductName: 九天科技V4.6版
ProductVersion: 4.6.0.0
CompanyName: 九天科技
LegalCopyright: 九天科技-投票软件
Comments: www.sky9vote.cn
Translation: 0x0804 0x04b0

Trojan.MauvaiseRI.S5257721 also known as:

LionicTrojan.Multi.Generic.4!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.3eca8f37d90aeca3
CAT-QuickHealTrojan.MauvaiseRI.S5257721
McAfeeArtemis!3ECA8F37D90A
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CyrenW32/OnlineGames.HH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9820446-0
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.RiskGen.dnvxjq
SophosGeneric PUA AJ (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminesuspicious.low.ml.score
IkarusTrojan.Win32.Vasdek
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1DNV50E
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C604990
VBA32BScope.Trojan.Fuery
MalwarebytesTrojan.MalPack.FlyStudio
YandexTrojan.GenAsa!eHQ3EXRHQAM
SentinelOneStatic AI – Malicious PE
FortinetRiskware/FlyStudio
AVGWin32:Malware-gen
Cybereasonmalicious.68f4d2
AvastWin32:Malware-gen

How to remove Trojan.MauvaiseRI.S5257721?

Trojan.MauvaiseRI.S5257721 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment