Trojan

MSIL/TrojanDownloader.Small.FG removal

Malware Removal

The MSIL/TrojanDownloader.Small.FG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Small.FG virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/TrojanDownloader.Small.FG?


File Info:

name: FF09ED6C59BBD0ED4D2B.mlw
path: /opt/CAPEv2/storage/binaries/0b2604d47f4a3645337216a9fef814848d9bbc5588286f19627fe7ddf07f41d3
crc32: 80D1978D
md5: ff09ed6c59bbd0ed4d2ba45485417371
sha1: ee50131c42eaecc259400ed1a03f81fcbe4d531e
sha256: 0b2604d47f4a3645337216a9fef814848d9bbc5588286f19627fe7ddf07f41d3
sha512: a13ff9173ad27b179f74c976b1355c0f5062dded85918e6de269a71372b02ad6308a87559f9ed6f183a59539c7b1eb9b7c6e194719b750f6f3f672bc5f3e9ffa
ssdeep: 3072:Ab90Wj4EqqDaxZss0mEHUIpQZh9h45Vr:Ab90qLLDMdWnpQZh9h4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15BB34951B9D1AB11C21434FADD6194D1423A2D8A6E01C713B6787B1F3EB20E7DFA32AD
sha3_384: d3bbcd7a453e6386e38abc7a07b3ad19c1adb5f34a28d6332794d29e4b421ac9cc8e2b8d1c939816337e555dbcb14df8
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-04-24 01:12:51

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: 123.exe
LegalCopyright:
OriginalFilename: 123.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/TrojanDownloader.Small.FG also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Barys.14335
FireEyeGeneric.mg.ff09ed6c59bbd0ed
ALYacGen:Variant.Barys.14335
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004d89951 )
K7GWTrojan-Downloader ( 004d89951 )
Cybereasonmalicious.c59bbd
BitDefenderThetaGen:NN.ZemsilF.34638.gm0@amdtlwl
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.FG
TrendMicro-HouseCallTROJ_GEN.R014C0PDR22
KasperskyHEUR:Trojan-Downloader.Win32.Generic
BitDefenderGen:Variant.Barys.14335
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan-downloader.Generic.Edxh
Ad-AwareGen:Variant.Barys.14335
EmsisoftGen:Variant.Barys.14335 (B)
TrendMicroTROJ_GEN.R014C0PDR22
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
AviraTR/Dropper.MSIL.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Barys.14335
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C4001487
Acronissuspicious
McAfeeGenericRXGG-ZY!FF09ED6C59BB
MAXmalware (ai score=84)
MalwarebytesBackdoor.Agent.PGen
RisingTrojan.Generic/MSIL@AI.90 (RDM.MSIL:HCctko+r1KZmd2Vl0kI8bA)
IkarusTrojan-Downloader.MSIL.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.AC4EA!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDownloader.Small.FG?

MSIL/TrojanDownloader.Small.FG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment