Trojan

MSIL/TrojanDownloader.Small.CIM removal

Malware Removal

The MSIL/TrojanDownloader.Small.CIM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Small.CIM virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

b.top4top.io
apps.identrust.com
winddns.zapto.org

How to determine MSIL/TrojanDownloader.Small.CIM?


File Info:

crc32: 4FD2453A
md5: 6ab121a18bf373b1091ff0e64d5136f2
name: 6AB121A18BF373B1091FF0E64D5136F2.mlw
sha1: 5f90c9215e79d341aa73148384bd7e8f8722f5e6
sha256: cc0bb6dde6f92cc12b0890f3c04ac8419f67ccb50c20992f8663d69eab6a67fe
sha512: 1606fe4624b875b6c91e73edfa3510f1706223293c83262fbd3564b674bde57c7f9dc3eb23d6e45aab58a10e29187b185aa841eb40679c415cb2b1079c123723
ssdeep: 768:vrfLrEzGL86GkEKz49WyJfFnlLhmjgepsy4qtiiiiiiiiiiiiiiiiiiiiiiiiii:7LYg86cj9U5eSYPIQ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: REEA
Assembly Version: 5.4.4.5
InternalName: tera.exe
FileVersion: 6.5.5.6
CompanyName: REEA
LegalTrademarks: REEA
Comments: REEA
ProductName: REEA
ProductVersion: 6.5.5.6
FileDescription: REEA
OriginalFilename: tera.exe

MSIL/TrojanDownloader.Small.CIM also known as:

MicroWorld-eScanTrojan.GenericKD.36081346
FireEyeGeneric.mg.6ab121a18bf373b1
Qihoo-360Generic/Backdoor.633
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
ZillyaBackdoor.Bladabindi.Win32.23079
AegisLabTrojan.MSIL.Bladabindi.m!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 00575c5f1 )
BitDefenderTrojan.GenericKD.36081346
K7GWTrojan-Downloader ( 00575c5f1 )
Cybereasonmalicious.15e79d
BitDefenderThetaGen:NN.ZemsilF.34804.em0@aSlhwe
CyrenW32/Trojan.YDIT-7795
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PAE21
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
AlibabaBackdoor:MSIL/Bladabindi.3ae8fe45
NANO-AntivirusTrojan.Win32.Bladabindi.ihwqpi
ViRobotTrojan.Win32.Z.Small.75776
RisingDownloader.Small!8.B41 (TFE:C:j1XmKLL6jdR)
Ad-AwareTrojan.GenericKD.36081346
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Small.bqqjj
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PAE21
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftTrojan.GenericKD.36081346 (B)
IkarusTrojan-Downloader.MSIL.Small
AviraTR/Dldr.Small.bqqjj
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Ymacco.AACC
ArcabitTrojan.Generic.D2268EC2
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
GDataTrojan.GenericKD.36081346
CynetMalicious (score: 90)
AhnLab-V3Malware/Win32.RL_Generic.C4316181
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.36081346
MalwarebytesTrojan.Downloader.MSIL
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.CIM
TencentMsil.Backdoor.Bladabindi.Wrqn
YandexTrojan.DL.Small!DBpvvfTaM2E
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_94%
FortinetMSIL/Small.CIM!tr.dldr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove MSIL/TrojanDownloader.Small.CIM?

MSIL/TrojanDownloader.Small.CIM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment