Trojan

How to remove “MSIL/TrojanDownloader.Small.AAP”?

Malware Removal

The MSIL/TrojanDownloader.Small.AAP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Small.AAP virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine MSIL/TrojanDownloader.Small.AAP?


File Info:

name: 777955F95F2615620DC4.mlw
path: /opt/CAPEv2/storage/binaries/9524db48a0239a59c300c86a670ffb3a9287b4b3384fc16161fa2da0b81a44e3
crc32: 7C3D1825
md5: 777955f95f2615620dc4e46790e7f8a1
sha1: 7f88a05b156020e1222a368ed8c864d890696257
sha256: 9524db48a0239a59c300c86a670ffb3a9287b4b3384fc16161fa2da0b81a44e3
sha512: 05295334bb9ba3126064f85ecd22550b5f330f96a64f5d2d809fc085d8ee1d519bf3933dd643eb41eb48a2c54755079b61a76e8461066f90ab1e1930ce70a065
ssdeep: 1536:36U7Mywd0Dj0QAHr+0Uk1IrmL6TmyDffMtFJuxzub:HAybj0QAL+0f1Z+SyDffoFec
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D73AE46F74C4106D8FD0FB5A4D69396273AEB4B8E229B5B10A4B04D0FF339269C16DE
sha3_384: 3c614f43fb7f156fda56c2231fa945a05c1b3f29ad7fd1e8c293865f0c296b5aa9750893497167a1ee499b62f0584ffc
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-10-01 05:57:28

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: Microsoft Word Document
FileVersion: 1.0.0.0
InternalName: filescan.exe
LegalCopyright: Microsoft Office Copyright © 2015
OriginalFilename: filescan.exe
ProductName: windowsscan
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Small.AAP also known as:

CynetMalicious (score: 99)
FireEyeIL:Trojan.MSILZilla.8300
MalwarebytesMalware.AI.2516567152
VIPREIL:Trojan.MSILZilla.8300
K7AntiVirusUnwanted-Program ( 700000121 )
K7GWUnwanted-Program ( 700000121 )
Cybereasonmalicious.95f261
VirITTrojan.Win32.DownLoader16.DJHR
CyrenW32/MSIL_Small.J.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.AAP
APEXMalicious
ClamAVWin.Spyware.CrimsonRat-9859243-0
KasperskyTrojan.MSIL.Agent.fofq
BitDefenderIL:Trojan.MSILZilla.8300
NANO-AntivirusTrojan.Win32.Dwn.dzwukj
MicroWorld-eScanIL:Trojan.MSILZilla.8300
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.12032ce6
Ad-AwareIL:Trojan.MSILZilla.8300
EmsisoftIL:Trojan.MSILZilla.8300 (B)
DrWebTrojan.DownLoader16.59011
ZillyaTrojan.Agent.Win32.585476
SophosTroj/Foreign-AF
IkarusTrojan-Downloader.MSIL.Small
GDataIL:Trojan.MSILZilla.8300
JiangminTrojan.Agent.akw
AviraHEUR/AGEN.1203635
Antiy-AVLTrojan/Generic.ASMalwS.2D
ArcabitIL:Trojan.MSILZilla.D206C
ZoneAlarmTrojan.MSIL.Agent.fofq
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C1133191
ALYacIL:Trojan.MSILZilla.8300
MAXmalware (ai score=80)
RisingDownloader.Small!8.B41 (TFE:dGZlOgyzV9xW7vLf0Q)
YandexTrojan.Agent!s/MyPycDqFA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.ACK!tr
BitDefenderThetaGen:NN.ZemsilF.34646.em2@aKC@wyf
AVGWin32:DropperX-gen [Drp]

How to remove MSIL/TrojanDownloader.Small.AAP?

MSIL/TrojanDownloader.Small.AAP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment