Trojan

What is “MSIL/TrojanDownloader.Small.BYF”?

Malware Removal

The MSIL/TrojanDownloader.Small.BYF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Small.BYF virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/TrojanDownloader.Small.BYF?


File Info:

name: 9D85A768E0C4BBCCF349.mlw
path: /opt/CAPEv2/storage/binaries/e1ce95956fb734de95860e8845b8c94db02d0fd48100d8224e1cae2e4ae5f32a
crc32: 0D8CB4D6
md5: 9d85a768e0c4bbccf3496dd3014e9c8a
sha1: bbd039bdca6a3cb9a3fed729c476da41ae925211
sha256: e1ce95956fb734de95860e8845b8c94db02d0fd48100d8224e1cae2e4ae5f32a
sha512: b934709c67386969da9b116ee89cd697f24bba8807b26bebc50bb97ad6e69e146731eebd516e5e116e87a4690abbf322b41932d8410e1662a61157f34c4953ae
ssdeep: 192:RxQG6kG+IYDMN11v7x5aQ9y38LH2N7VeRocDT:RyG6kG7R5aQ98RVemcD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15022B70176648666F27A0B7EC4FBB2547376FB12EF129B0D6C8D620D48537E04E039EA
sha3_384: 535058b7b44a16c04c9e23a9fd78a2e275d580e3fc2a959a09f517501a7cc4e5ba962529e6574fbaa73b86cb9b07c995
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-11-12 20:02:33

Version Info:

Translation: 0x0000 0x04b0
Comments: ?(_.^?`.`*!.&@[_^,=?
CompanyName: .,;<_@~^..;*~~^.`^[$
FileDescription: **!~`@,<;,-*!$`.;[.`
FileVersion: 0.0.0.0
InternalName: 989978969679679.exe
LegalCopyright: ;@_*-;`.$^<;*.^_.@.@
LegalTrademarks: ;@__$;@-:!^^,~.`_%_^
OriginalFilename: 989978969679679.exe
ProductName: ,<*%$.!.*.,~;-`,.^*-
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/TrojanDownloader.Small.BYF also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.9d85a768e0c4bbcc
McAfeeArtemis!9D85A768E0C4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforBackdoor.Win32.Bladabindi.ml
K7AntiVirusTrojan-Downloader ( 0054ef8d1 )
AlibabaTrojan:MSIL/Startun.1cbbac89
K7GWTrojan-Downloader ( 0054ef8d1 )
Cybereasonmalicious.8e0c4b
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.BYF
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Startun.gen
BitDefenderTrojan.GenericKD.44516877
NANO-AntivirusTrojan.Win32.Startun.icaahs
MicroWorld-eScanTrojan.GenericKD.44516877
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Trojan.Startun.Hwmn
Ad-AwareTrojan.GenericKD.44516877
EmsisoftTrojan.GenericKD.44516877 (B)
DrWebTrojan.DownLoader35.33560
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.44516877
JiangminTrojan.MSIL.tgnd
AviraTR/Downloader.Gen8
MAXmalware (ai score=81)
ArcabitTrojan.Generic.D2A7460D
ZoneAlarmHEUR:Trojan.MSIL.Startun.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZemsilF.34212.am0@aOImeod
ALYacTrojan.GenericKD.44516877
VBA32TScope.Trojan.MSIL
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:gfKjJJepEjLbsth+VgsT+g)
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Small.BYF!tr.dldr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDownloader.Small.BYF?

MSIL/TrojanDownloader.Small.BYF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment