Backdoor

Backdoor:Win32/Small.CG information

Malware Removal

The Backdoor:Win32/Small.CG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Small.CG virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor:Win32/Small.CG?


File Info:

name: 98C3C779015914B4FE9C.mlw
path: /opt/CAPEv2/storage/binaries/2bbf45cbcfc69469913dd12e3673f3fe3e36a10516e92d0c246332da3cb49729
crc32: 8D7105DF
md5: 98c3c779015914b4fe9ca1381d6e4e5b
sha1: 0acd9f5169ec7a6cc769524ab02aadea0e8f9d2c
sha256: 2bbf45cbcfc69469913dd12e3673f3fe3e36a10516e92d0c246332da3cb49729
sha512: 0e968f10f460dd34014669a853fe1997ea1914ba3d42fe6f61bc3efb6f883b374eb3e26fe3fee2ba1ed7215a26b756bd3975deba9056614ea159f328746aaead
ssdeep: 12288:EAjF4ASEV4H8pPyoQBOyGw0fpKkvTAlQT97EElOPh1vjztwbnE:ZjKFEVwSdQBdMpxvh9dlwjztwbnE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T118152BE2497AD172C4EAB31AADFF6FAE6B35DB4260D0231741126BC05A1373275036ED
sha3_384: 8f87e67c007c91148b16784a8ae37c7a2cbcb3b96abfd661e3da34dd65e86c1599201ab8562502a9f8853c989ec9a016
ep_bytes: ff250020400000000000000000000000
timestamp: 2013-08-11 10:19:57

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: سيرفر1.exe
LegalCopyright:
OriginalFilename: سيرفر1.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Backdoor:Win32/Small.CG also known as:

DrWebTrojan.DownLoader9.48551
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
FireEyeGeneric.mg.98c3c779015914b4
VIPREGen:Heur.MSIL.Bladabindi.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e39b1 )
AlibabaBackdoor:MSIL/Bladabindi.a159eb14
K7GWTrojan ( 0055e39b1 )
Cybereasonmalicious.901591
BitDefenderThetaGen:NN.ZemsilF.34646.6m0@aKgqMmo
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.UP
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.Bladabindi.dkmpln
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Heur.MSIL.Bladabindi.1
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
ComodoMalware@#145lt3s2ho0kq
ZillyaDropper.Agent.Win32.421544
McAfee-GW-EditionBehavesLike.Win32.Generic.dt
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraHEUR/AGEN.1221809
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Small.CG
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
GDataGen:Heur.MSIL.Bladabindi.1
CynetMalicious (score: 99)
Acronissuspicious
McAfeeArtemis!98C3C7790159
MAXmalware (ai score=88)
TencentMsil.Backdoor.Bladabindi.Swhl
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Dropper.WT!tr
AVGWin32:DropperX-gen [Drp]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Small.CG?

Backdoor:Win32/Small.CG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment