Trojan

MSIL/TrojanDownloader.Tiny.BFW removal instruction

Malware Removal

The MSIL/TrojanDownloader.Tiny.BFW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Tiny.BFW virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine MSIL/TrojanDownloader.Tiny.BFW?


File Info:

name: F290C339179A5E260C23.mlw
path: /opt/CAPEv2/storage/binaries/06021086422a39727cd47285cbe01fdcc0236581e25e639c5005ca5442e2ff72
crc32: 80D5DB2F
md5: f290c339179a5e260c23f229c1ccddd7
sha1: cf4b807be056f9983afbf9379466f62c60e3bc69
sha256: 06021086422a39727cd47285cbe01fdcc0236581e25e639c5005ca5442e2ff72
sha512: 30135be62afcf2297b34a964f286539a4a6c93e1bf438fc2baf074c032631e86a59762a557b0830ab9ff1bbac70ec5b4d50c9348ce0164b24442b9cb032e7f90
ssdeep: 96:qqnsCEGLurKOdJxH+FX0sbKg036JDxl8n41Eq1xlFFC7058C7YczNt:qGEmmzsmT36Nj8n4171j158Nm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4E1A5D89FFC4633E77E8F3819A2A600B634A2236D338F5F14C1911B5D352162DA1778
sha3_384: c374586f036d1f3806a95bfdd478a98d5212ce5168f6dad32c93e51bd2041eef1eda1bbaa7bfca25cec4e064d75117f1
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-09-09 13:09:09

Version Info:

Translation: 0x0000 0x04b0
Comments: Installer
CompanyName: Technology Co. Ltd.
FileDescription: Installer
FileVersion: 7.0.1.5
InternalName: chltJ
LegalCopyright: Copyright (C) 2021 Online Inc. All rights reserved.
OriginalFilename: chltJ
ProductVersion: 7.0.1.5
Assembly Version: 0.0.0.0

MSIL/TrojanDownloader.Tiny.BFW also known as:

MicroWorld-eScanTrojan.GenericKD.38094180
FireEyeGeneric.mg.f290c339179a5e26
McAfeeArtemis!F290C339179A
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZemsilF.34294.am0@aWdD37h
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Tiny.BFW
TrendMicro-HouseCallTROJ_GEN.R002H0DKM21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.NanoBot.gen
BitDefenderTrojan.GenericKD.38094180
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.38094180
McAfee-GW-EditionArtemis!Trojan
SophosGeneric ML PUA (PUA)
IkarusTrojan-Downloader.MSIL.Tiny
GDataTrojan.GenericKD.38094180
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.38094180
MAXmalware (ai score=84)
MalwarebytesTrojan.Downloader.MSIL.Generic
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Agent.IQL!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove MSIL/TrojanDownloader.Tiny.BFW?

MSIL/TrojanDownloader.Tiny.BFW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment