Malware

MSIL/Small.FU removal tips

Malware Removal

The MSIL/Small.FU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Small.FU virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • CAPE detected the CoinMiner03 malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine MSIL/Small.FU?


File Info:

name: CD99CD64D0DEB3FE2AA4.mlw
path: /opt/CAPEv2/storage/binaries/d0dded8ecbf82c531ed2cb8e2ff82e621b34660416495e9481471a8fa358dd71
crc32: B9D170A0
md5: cd99cd64d0deb3fe2aa4919f3abfcd55
sha1: 71df99092ad7c3132e590a265bb640b463365ac3
sha256: d0dded8ecbf82c531ed2cb8e2ff82e621b34660416495e9481471a8fa358dd71
sha512: d418074ea14c026339c9b8304f0cb39a266287490c14285f387e36d73cf384339e830591adacfff384fb62ddc3be90f2f02fc3b536c2284a75761a7429d1ed5a
ssdeep: 12288:lT52MR9Rcx03JYEuTbGQQg8UAfw+mnxtB5i1:1CxrO+Afwnx7w1
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T184D4D81512FAD0633273896D8BC9DA34F813C8EA98845C3536CB40999799E40B5FF6EF
sha3_384: 20542d60a97fd5e398f5aeb279292100649f9f9fd92fc575c8a869d335add7366ade63fc79f62e278a55f312205eea4d
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2042-05-01 12:38:03

Version Info:

Translation: 0x0000 0x04b0
Comments: MicrosoftApi
CompanyName: Microsoft
FileDescription: MicrosoftApi
FileVersion: 0.1.4.8
InternalName: MicrosoftApi.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: MicrosoftApi.exe
ProductName: Api
ProductVersion: 0.1.4.8
Assembly Version: 2.33.0.6

MSIL/Small.FU also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.7318
MicroWorld-eScanTrojan.GenericKD.37311015
CAT-QuickHealTrojan.MsilFC.S22017815
McAfeeArtemis!CD99CD64D0DE
CylanceUnsafe
ZillyaTrojan.SpyEyes.Win32.15391
SangforTrojan.MSIL.SpyEyes.gen
K7AntiVirusTrojan ( 0054594d1 )
AlibabaTrojanSpy:MSIL/SpyEyes.c2f2b9c1
K7GWTrojan ( 0054594d1 )
Cybereasonmalicious.92ad7c
CyrenW64/Trojan.SVGD-4039
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Small.FU
TrendMicro-HouseCallTROJ_GEN.R01FC0WGV21
Paloaltogeneric.ml
ClamAVWin.Packed.Spyeye-9883275-0
KasperskyHEUR:Trojan-Spy.MSIL.SpyEyes.gen
BitDefenderTrojan.GenericKD.37311015
NANO-AntivirusTrojan.Win64.SpyEyes.ixwvsn
AvastWin64:Trojan-gen
Ad-AwareTrojan.GenericKD.37311015
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R01FC0WGV21
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.cd99cd64d0deb3fe
EmsisoftTrojan.GenericKD.37311015 (B)
IkarusTrojan.MSIL.Small
GDataMSIL.Trojan.Miner.C
MaxSecureTrojan.Malware.73890143.susgen
AviraTR/Small.dplwb
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftMalware.Win64.GenericMC.cc
MicrosoftTrojan:Win32/AgentTesla!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4571017
VBA32TrojanSpy.MSIL.SpyEyes
ALYacSpyware.SpyEyes
MalwarebytesSpyware.Agent
APEXMalicious
TencentMsil.Trojan-spy.Spyeyes.Tbsj
MAXmalware (ai score=83)
FortinetW32/SpyEyes.FU!tr
WebrootW32.Trojan.Gen
AVGWin64:Trojan-gen
PandaTrj/RnkBend.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Small.FU?

MSIL/Small.FU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment