Trojan

MSIL/TrojanDownloader.Small.IC malicious file

Malware Removal

The MSIL/TrojanDownloader.Small.IC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Small.IC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to execute a binary from a dead or sinkholed URL
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
higgs.rghost.ru
rghost.net

How to determine MSIL/TrojanDownloader.Small.IC?


File Info:

crc32: 6B8C7F67
md5: c7315431ac3055dcf589637d9c5a62a7
name: C7315431AC3055DCF589637D9C5A62A7.mlw
sha1: b8970aab20aede1a05b75921e73979573fa7d097
sha256: 2123dbac8752ad0dd8e1dfc487b43cb15120e26f172c11f5824d039dd18c266c
sha512: 502b879cf53e2ac643079c0a60df87bf34ee7a3f0065ff8d132c604971e17535cf50694dc4fc0a63140098046cbd23afbc044032acf77f19fb48d7646525fad8
ssdeep: 3072:CNjeqIScg9RcCuqk5qofO6gy894lTge8V4L97JU2eN:CNiqISNP69fq94luIJU2
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2005
Assembly Version: 4.6.8.37
InternalName: 1.exe
FileVersion: 6.8.10.41
CompanyName: aomKRaJYChFF
LegalTrademarks: aSTMVycqyt8KLru
ProductName: a99do5azM4GbG
ProductVersion: 6.8.10.41
FileDescription: aFgREXPDEeT
OriginalFilename: 1.exe

MSIL/TrojanDownloader.Small.IC also known as:

K7AntiVirusTrojan-Downloader ( 0049aeea1 )
LionicTrojan.MSIL.Generic.a!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.MSIL.Vuvazi.C.2
CylanceUnsafe
SangforTrojan.Win32.Small.8
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0049aeea1 )
Cybereasonmalicious.1ac305
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.IC
APEXMalicious
AvastMSIL:Agent-BHB [Trj]
KasperskyHEUR:Trojan-Downloader.MSIL.Generic
BitDefenderGen:Heur.MSIL.Vuvazi.C.2
NANO-AntivirusTrojan.Win32.Kazy.dbfvqk
MicroWorld-eScanGen:Heur.MSIL.Vuvazi.C.2
TencentWin32.Trojan.Generic.Sxdx
Ad-AwareGen:Heur.MSIL.Vuvazi.C.2
SophosMal/Generic-R + Mal/Dotnet-Q
BitDefenderThetaGen:NN.ZemsilF.34294.jm0@a4ogUjk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic Downloader.x
FireEyeGeneric.mg.c7315431ac3055dc
EmsisoftGen:Heur.MSIL.Vuvazi.C.2 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1103774
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Heur.MSIL.Vuvazi.C.2
AhnLab-V3Malware/Win32.RL_Generic.C4242355
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=88)
YandexTrojan.DL.Small!Xg4AJLm51w8
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Small.IC!tr.dldr
AVGMSIL:Agent-BHB [Trj]
Paloaltogeneric.ml

How to remove MSIL/TrojanDownloader.Small.IC?

MSIL/TrojanDownloader.Small.IC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment