Trojan

About “Trojan.SchoolBoy” infection

Malware Removal

The Trojan.SchoolBoy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.SchoolBoy virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Trojan.SchoolBoy?


File Info:

name: 5E422A91F90BD6129217.mlw
path: /opt/CAPEv2/storage/binaries/372cdd9195367cf53630b3658737fae16626dc058c5558db420a62b028d431e7
crc32: 5F3EA588
md5: 5e422a91f90bd6129217384826bc9fdc
sha1: fe11e1c94eda338448ffe975e2c171fa31f90281
sha256: 372cdd9195367cf53630b3658737fae16626dc058c5558db420a62b028d431e7
sha512: 01a380e024bd4cdaa2539cfd875e3f12e764098a502a6f10f50b7b515079e74ee4931bde236ac7838b01ce2e3ed2cef4a78879b0af011d544619a97f180f79b9
ssdeep: 12288:NV+mzc1x5DlUfl9jNpWUdxAG8wS7AOOnT1w5US+UiL4aFH/eD0KD:N8zD69HtAGE7HTr+UiL4aFHmAs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6B41219B74680F7C880163099CC6BBAF57CEB357390A18BF7960D4D7C74692A40B6BA
sha3_384: 30e8a182663228dbf9dee2dafbd68a3d6d825f7b9fcb8722a488bb6060e0aa21dbd3a6059bdab539e38d34f98c639404
ep_bytes: e8f32a000050e83b3301000000000090
timestamp: 2007-09-20 12:34:46

Version Info:

0: [No Data]

Trojan.SchoolBoy also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.30709371
FireEyeTrojan.GenericKD.30709371
ALYacTrojan.GenericKD.30709371
CylanceUnsafe
ZillyaTrojan.SchoolBoyCRTD.Win32.10611
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.30709371
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1f90bd
SymantecTrojan.Gen.MBT
KasperskyUDS:Trojan.Win32.SchoolBoy.fm
NANO-AntivirusTrojan.Win64.SchoolBoy.fcbndn
SophosGeneric PUA FO (PUA)
DrWebTrojan.Siggen12.32198
McAfee-GW-EditionRDN/Generic.grp
EmsisoftTrojan.GenericKD.30709371 (B)
APEXMalicious
JiangminTrojan.Schoolboy.fw
AviraTR/Strictor.lbwpq
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.2523C5F
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.30709371
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.C4952775
McAfeeArtemis!5E422A91F90B
VBA32Trojan.SchoolBoy
MalwarebytesMalware.AI.4242759449
YandexTrojan.SchoolBoy!TRUMFx5urm4
IkarusTrojan.Win64.Agent
FortinetW32/SchoolBoy.QH!tr
AVGFileRepMalware
AvastFileRepMalware

How to remove Trojan.SchoolBoy?

Trojan.SchoolBoy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment