Trojan

Trojan.Win32.SchoolBoy removal

Malware Removal

The Trojan.Win32.SchoolBoy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.SchoolBoy virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Trojan.Win32.SchoolBoy?


File Info:

name: 2AA52F7209192A868F6A.mlw
path: /opt/CAPEv2/storage/binaries/96fdf95287e374e3ea5a18fa9e65bfc5d39869f8e16834b28917dfa0c4278abc
crc32: FEC2616F
md5: 2aa52f7209192a868f6ab9db05fcfeac
sha1: e2e590ac4c6e302732562fbefc2c8854e8d2eccf
sha256: 96fdf95287e374e3ea5a18fa9e65bfc5d39869f8e16834b28917dfa0c4278abc
sha512: 7bfdec20f24cd86ae0e3d02211a6de21d624e46baf288fd46f2338cc90cd2e6d10a9ad48cae83d9826438339a1b0a062d2f8d16a69084e2e04aeb797be75b3ba
ssdeep: 24576:/HPS4CrMIL/KDye9jYOJPU+SyDnTmbEdBJzWD8qA4IjyCs9uRAHzNZyxfoRGLh5V:/mrMIbKDye9jYOJPU+SyDKbeJzYvAXjT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6650201F7C3D1B0CA6212311E56FF2A90EDB6749B264ED3BBD80E4C1A315E1B639766
sha3_384: 6ea5c09bd39af1dcb906dcb69febe919834b460712371a3f4f3bec990314163a727e1f7a784328047b737735b821c8bd
ep_bytes: e8443a0000e97ffeffff538bdc515183
timestamp: 2019-02-22 03:23:18

Version Info:

FileVersion: 5.9.8.10920
ProductVersion: 5.9
Translation: 0x0804 0x04b0

Trojan.Win32.SchoolBoy also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.2aa52f7209192a86
ALYacGen:Variant.Midie.88217
Cybereasonmalicious.c4c6e3
VirITTrojan.Win32.Muldrop8.CQAV
CyrenW32/SchoolBoy.A.gen!Eldorado
APEXMalicious
ClamAVWin.Malware.Mikey-6986881-0
KasperskyHEUR:Trojan.Win32.SchoolBoy.gen
BitDefenderGen:Variant.Midie.88217
NANO-AntivirusRiskware.Win32.HackTool.gggyda
MicroWorld-eScanGen:Variant.Midie.88217
TencentWin32.Trojan.Schoolboy.Htmj
EmsisoftGen:Variant.Midie.88217 (B)
ComodoTrojWare.Win32.Eqtonex.B@83htfq
ZillyaTrojan.Miner.Win32.5421
TrendMicroTROJ_GEN.R035C0WB222
McAfee-GW-EditionBehavesLike.Win32.PUPXFM.tc
SophosGeneric ML PUA (PUA)
AviraHEUR/AGEN.1204271
MAXmalware (ai score=81)
MicrosoftTrojan:Script/Phonzy.C!ml
ZoneAlarmHEUR:Trojan.Win32.SchoolBoy.gen
GDataGen:Variant.Midie.88217
AhnLab-V3Malware/Win.Generic.R452636
McAfeeArtemis!2AA52F720919
MalwarebytesPUP.Optional.ChinAd
TrendMicro-HouseCallTROJ_GEN.R035C0WB222
YandexPUP.Crack!9ZqoJCZNjeQ
Ikaruspossible-Threat.Untrusted.Certificate
eGambitUnsafe.AI_Score_52%
FortinetW32/PossibleThreat
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Win32.SchoolBoy?

Trojan.Win32.SchoolBoy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment