Trojan

MSIL/TrojanDownloader.Small.DAP removal

Malware Removal

The MSIL/TrojanDownloader.Small.DAP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Small.DAP virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Creates a copy of itself
  • Binary compilation timestomping detected
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine MSIL/TrojanDownloader.Small.DAP?


File Info:

name: 21BE7D066BA92CC07EC1.mlw
path: /opt/CAPEv2/storage/binaries/52568b069b5bc10ad7f11c1106da3a196a443a6a7ef424fcb46977d2b775d547
crc32: 5FF3D879
md5: 21be7d066ba92cc07ec118109a53281e
sha1: 2deb67fbe6f1953a5e1449a3727d6b16734039aa
sha256: 52568b069b5bc10ad7f11c1106da3a196a443a6a7ef424fcb46977d2b775d547
sha512: 35ff21f05bab11a5d9d53dc8079524cbf77ad219ec0e6645cc4e31cf65ee4744a3b9320398f3b02f87cfc9f2ab1ee9e847f1781d002167a783761094f5b35569
ssdeep: 192:Qdfe13HRtwsGbs8QaPh1MgMwftWfBxsW2:QQHrwsGbdPhNMwftWfBxsW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10922B70163E48324FAFE4B799D3397105B36BE468936CE9E0960A68F1C327548D93BB5
sha3_384: 461ea45c54fe7e9760ef3a32cdff2561f5eb31b7c671611a7ce203ca77b6b42c35403df6c9d007461695aa41803a76a6
ep_bytes: ff250020400000000000000000000000
timestamp: 2079-08-04 20:55:13

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Registry Editor
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: REGEDIT
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: REG.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

MSIL/TrojanDownloader.Small.DAP also known as:

BkavW32.Common.28424985
LionicTrojan.Win32.Tasker.1g!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68232971
FireEyeGeneric.mg.21be7d066ba92cc0
ALYacTrojan.GenericKD.68232971
Cylanceunsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.be6f19
BitDefenderThetaGen:NN.ZemsilF.36318.am0@aCPjZ4li
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/TrojanDownloader.Small.DAP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Tasker.gen
BitDefenderTrojan.GenericKD.68232971
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.13ba3cd5
EmsisoftTrojan.GenericKD.68232971 (B)
F-SecureHeuristic.HEUR/AGEN.1352192
VIPRETrojan.GenericKD.68232971
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.68232971
AviraHEUR/AGEN.1352192
Antiy-AVLTrojan/MSIL.Tasker
ArcabitTrojan.Generic.D411270B
ZoneAlarmHEUR:Trojan.MSIL.Tasker.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!21BE7D066BA9
MAXmalware (ai score=83)
PandaTrj/Chgt.AD
RisingDownloader.Small!8.B41 (CLOUD)
FortinetPossibleThreat
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDownloader.Small.DAP?

MSIL/TrojanDownloader.Small.DAP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment