Trojan

Trojan.Win32.SchoolBoy.bad malicious file

Malware Removal

The Trojan.Win32.SchoolBoy.bad is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.SchoolBoy.bad virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Trojan.Win32.SchoolBoy.bad?


File Info:

name: 2C3179B22A315467B3C0.mlw
path: /opt/CAPEv2/storage/binaries/03e248dafb77a09221bb707f79bed021f273d2a54ac7a11116a9dd9b2dcaffa3
crc32: BC766A7C
md5: 2c3179b22a315467b3c046cb42f29ba0
sha1: 5ba911b454d6bac56f0118ac6bb4a78a845fd6b6
sha256: 03e248dafb77a09221bb707f79bed021f273d2a54ac7a11116a9dd9b2dcaffa3
sha512: 001b319196136f88dd00f108c6fb9e98f860bf40a43cacca738b3c5cbe645ad3caba991ad9573ee4c84e7f477b8397caf0daac0087f530206194005f7f07872d
ssdeep: 98304:8Ax3KgVKbTm68bZ4lIhpHMqcPn28gCDSc94hHK:8cLbLylILMqfOSDhq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122F533E7BA950038D8B75F3D5C6AA9760603CC1C43E60EA15BB07BC25DA1A84DDE0F27
sha3_384: aab73ab9318ba5e003ece92ec0c1a70573026a9f7247d1d2879034a902246e3f2df8c8b1fa8a1be3c7343a7e5a7246d5
ep_bytes: 60be00f048008dbe0020f7ff57eb0b90
timestamp: 2011-09-11 18:12:22

Version Info:

FileVersion: 1.6.8.8
Comments: WindowsNT6快速设置工具最终版
FileDescription: WindowsNT6快速设置工具是一款对系统进行快捷设置增强优化的小工具.
LegalCopyright: 虫子樱桃
技术支持论坛: ta.com.cn
作者博客: zyt.blog.com
Translation: 0x0804 0x04b0

Trojan.Win32.SchoolBoy.bad also known as:

LionicTrojan.Win32.SchoolBoy.4!c
Elasticmalicious (moderate confidence)
DrWebTrojan.Siggen10.42837
MicroWorld-eScanTrojan.GenericKD.50235582
FireEyeTrojan.GenericKD.50235582
ALYacTrojan.GenericKD.50235582
CylanceUnsafe
SangforTrojan.Win32.SchoolBoy.bad
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/SchoolBoy.739716c1
K7GWTrojan ( 700000111 )
SymantecTrojan.Gen.2
TrendMicro-HouseCallMal_Otorun-13
ClamAVWin.Virus.Parite-6777121-0
KasperskyTrojan.Win32.SchoolBoy.bad
BitDefenderTrojan.GenericKD.50235582
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114bc2de
Ad-AwareTrojan.GenericKD.50235582
SophosMal/Generic-S
ComodoTrojWare.Win32.Hider.REXS@5364kt
TrendMicroMal_Otorun-13
McAfee-GW-EditionBehavesLike.Win32.Injector.wc
EmsisoftTrojan.GenericKD.50235582 (B)
GDataTrojan.GenericKD.50235582
MAXmalware (ai score=89)
KingsoftWin32.Troj.Generic.v.(kcloud)
ArcabitTrojan.Generic.D2FE88BE
ZoneAlarmTrojan.Win32.SchoolBoy.bad
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!2C3179B22A31
VBA32Trojan.Autoit.F
MalwarebytesMalware.Heuristic.1003
APEXMalicious
YandexTrojan.Pincav!27DQR27eSEQ
AVGWin32:Trojan-gen

How to remove Trojan.Win32.SchoolBoy.bad?

Trojan.Win32.SchoolBoy.bad removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment