Trojan

Trojan.Win32.SchoolBoy.ndi malicious file

Malware Removal

The Trojan.Win32.SchoolBoy.ndi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.SchoolBoy.ndi virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.SchoolBoy.ndi?


File Info:

name: 9F054F997ED5AC06F719.mlw
path: /opt/CAPEv2/storage/binaries/5dac8b34632e0cdcd1fb4b74bb96bb0fcc53e3a6d781921487e8845e0985fda8
crc32: 1EFDAC7E
md5: 9f054f997ed5ac06f7198a4e68619f94
sha1: 27d1d557ee0e658f8ea0bae491ed4d01f8e9c7ee
sha256: 5dac8b34632e0cdcd1fb4b74bb96bb0fcc53e3a6d781921487e8845e0985fda8
sha512: 320fcece2c510277c4a0f9be0000d01b3a112c6bc25778ea202fa7b7f038a3c6aeacafd19cc0843db23c029716fe6608cb2dcb6967685fb234338f2239da2889
ssdeep: 6144:vWUBO17MqRgofChE4DQ8F6qLvp9qynbfh2bCipkCk3euWC3AOG4g562:v3BNNThEEF6qLvp9qynbfhWU3euWC33m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9648D1175E2C432D462113649B4D7B6493EB8304B6596EBB3C80B7EDF303C2AB75A6B
sha3_384: f8f64b744238eeebeb7ebe3124ce645823d79255b1a77d9533181e776d1921e2f93df52c684c368a7ae51e38e74bfb98
ep_bytes: e8623c0000e995feffff8bff558bec81
timestamp: 1970-01-01 05:23:36

Version Info:

0: [No Data]

Trojan.Win32.SchoolBoy.ndi also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.RP.tyX@bq@7gJjj
FireEyeGeneric.mg.9f054f997ed5ac06
McAfeeGenericRXAA-AA!9F054F997ED5
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/MalwareX.7653a302
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.SchoolBoy.ndi
BitDefenderGen:Trojan.Heur.RP.tyX@bq@7gJjj
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Dropper.Hufl
Ad-AwareGen:Trojan.Heur.RP.tyX@bq@7gJjj
SophosMal/Generic-S
ComodoTrojWare.Win32.ButeRat.PP@4roeaa
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WBI22
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
EmsisoftGen:Trojan.Heur.RP.tyX@bq@7gJjj (B)
IkarusTrojan.Win32.Agent
GDataGen:Trojan.Heur.RP.tyX@bq@7gJjj
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3102DB5
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Ymacco.AA5D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.R354757
BitDefenderThetaAI:Packer.5144EADB1F
ALYacGen:Trojan.Heur.RP.tyX@bq@7gJjj
MAXmalware (ai score=85)
VBA32Trojan.Ymacco
MalwarebytesMalware.AI.1996284191
TrendMicro-HouseCallTROJ_GEN.R002H0CB822
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.DR.Agent!L6ooOP/nfiM
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetPossibleThreat.PALLAS.H
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.97ed5a
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.SchoolBoy.ndi?

Trojan.Win32.SchoolBoy.ndi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment