Malware

MSIL/Small.KQ removal guide

Malware Removal

The MSIL/Small.KQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Small.KQ virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Small.KQ?


File Info:

name: 2434B508CF7D2769B0A9.mlw
path: /opt/CAPEv2/storage/binaries/6b7af664db5443fe81ad36558622c8da72359646bb7cabe6af829dba1e541114
crc32: 8484F698
md5: 2434b508cf7d2769b0a993c0a9cc59e2
sha1: 599693b592ba90922c7e5bcae84d7b97ec3f560b
sha256: 6b7af664db5443fe81ad36558622c8da72359646bb7cabe6af829dba1e541114
sha512: 4c0a3d463d3b503152612c1dd6e8fb0e7f63626599241b3c077ffabf5c57f811394c67bc8e425729a8e7eed52ab50de9a5da35d53761a979e1b4368d80c9ca46
ssdeep: 192:G6Vj/tUIyZK0vLZa76gL92DIzPBL1LZDZylG8vISduUSqD:b9OI0LZa7tLYDIzPBL1LhZMG81uUSq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16912F724F7E48339D53A0A7698A393A04739D3559C63DA6E788C31066E533610EA3FF5
sha3_384: fef1ea28528e26601b7b96896c4f60b700faed7186e20e935b8219183257039ff3617c788311a1869a5229c7d14b9dba
ep_bytes: ff250020400000000000000000000000
timestamp: 2085-06-09 10:27:55

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WindowsFormsApp8
FileVersion: 1.0.0.0
InternalName: WindowsFormsApp8.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: WindowsFormsApp8.exe
ProductName: WindowsFormsApp8
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Small.KQ also known as:

BkavW32.AIDetectNet.01
FireEyeGeneric.mg.2434b508cf7d2769
CylanceUnsafe
SangforTrojan.Msil.Agent.Vt4l
AlibabaTrojan:MSIL/Generic.532a10f7
BitDefenderThetaGen:NN.ZemsilCO.34742.am0@am@AIMp
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Small.KQ
Paloaltogeneric.ml
AvastWin32:Trojan-gen
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA FJ (PUA)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!2434B508CF7D
APEXMalicious
RisingTrojan.Generic/MSIL@AI.96 (RDM.MSIL:uCVvacylhDwzLgYpOa5vcw)
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove MSIL/Small.KQ?

MSIL/Small.KQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment