Trojan

How to remove “MSIL/TrojanDownloader.Small.CXA”?

Malware Removal

The MSIL/TrojanDownloader.Small.CXA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Small.CXA virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Small.CXA?


File Info:

name: 21F54614B21E9408C9C9.mlw
path: /opt/CAPEv2/storage/binaries/05c84473fa923a0f8aff3304439749f829dd3c9b48839792adc4565ae408ddb7
crc32: C066E257
md5: 21f54614b21e9408c9c9cd9a7e25f8ca
sha1: d7386eafa399d9246016c3982b207a2791df0637
sha256: 05c84473fa923a0f8aff3304439749f829dd3c9b48839792adc4565ae408ddb7
sha512: 016ce4d41bd51c1ca7587aa4cc4c7aa2facabb5106374b2764c0152a0f3fe97d72b41732c03b8c025516144756510b5aee016517ae4796cb09682e0a76efbbf6
ssdeep: 96:dM4Z8oQRhNeH3RVn5/rI/9zD1TIoD2LJG1OxfWdVWwGzNt:d5Z8oTXL5E/DoL81OxfWdVWN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11CF11801B3EA0B31ED774B765D73E3411ABEE755285BC76E34C0604E7D12A900A62BBA
sha3_384: 65edac45e712c27b99f6cdbfc4a238c493d77335a2c1560d56b214f296e16962077607103e468b2208c0df798adef783
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-16 15:25:50

Version Info:

Translation: 0x0000 0x04b0
Comments: COM Surrogate
CompanyName: Microsoft Corporation
FileDescription: COM Surrogate
FileVersion: 10.0.17763.1
InternalName: Pxmyhqu.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: Pxmyhqu.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17763.1
Assembly Version: 10.0.17763.1

MSIL/TrojanDownloader.Small.CXA also known as:

BkavW32.AIDetectNet.01
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZemsilF.34646.am0@ai6GBQo
SymantecMSIL.Downloader!gen8
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.CXA
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
AvastDropperX-gen [Drp]
TencentWin32.Trojan.Generic.Pzfl
SophosTroj/DwnLd-AFX
SentinelOneStatic AI – Suspicious PE
GoogleDetected
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
VBA32Downloader.MSIL.gen.rexp
MalwarebytesTrojan.Downloader.MSIL.Generic
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Kryptik.AGKN!tr
AVGDropperX-gen [Drp]

How to remove MSIL/TrojanDownloader.Small.CXA?

MSIL/TrojanDownloader.Small.CXA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment