Trojan

About “Trojan.Downloader.Small.ABNE” infection

Malware Removal

The Trojan.Downloader.Small.ABNE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.Small.ABNE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Downloader.Small.ABNE?


File Info:

name: 7650F5DB4133AE95537D.mlw
path: /opt/CAPEv2/storage/binaries/b780df20f33114446b50062cf673c04a34fea1d124d90483bbd935ececf1e356
crc32: E9CC3966
md5: 7650f5db4133ae95537dbf525075228c
sha1: 579cd594bc3f7f59fd305da0b997282a3e166475
sha256: b780df20f33114446b50062cf673c04a34fea1d124d90483bbd935ececf1e356
sha512: 38f8d509f799d79cea31f0fb0600d6044395938748743e109b3775f9ee6c7706aa5eab68d84df039c917a053959a422ef93d27c47b917e9355cdc96ae9a5f1f5
ssdeep: 384:uYJMpHtdEI2MyzNORCFtOflIwo59NM2XBFV7WB7lx7+sBr5sWL67q/9D5YxOdfVC:7WRtdEI2MyzNORQtOflIwoHNM2XBFV7Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FB208B1FAC414D1E46361B7F8BBAAC164177F9E7466490D20897F098AF3361B4A180F
sha3_384: 7e93435737e46243228a24f719015392d4916769da0fcfc55efcebb381d1e826f7efbbf1904199cab39a556eade60e25
ep_bytes: bbd0014000bf00104000bea2b9400053
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Downloader.Small.ABNE also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.Small.ABNE
FireEyeGeneric.mg.7650f5db4133ae95
SkyhighBehavesLike.Win32.Generic.mh
McAfeePWSZbot-FIT!297D34D15105
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Downloader.Small.ABNE
K7AntiVirusTrojan ( 00544ddf1 )
K7GWTrojan ( 00544ddf1 )
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SMZ9
AvastWin32:Trojan-gen
ClamAVWin.Downloader.Bublik-10025883-0
KasperskyTrojan.Win32.Bublik.bjqt
BitDefenderTrojan.Downloader.Small.ABNE
NANO-AntivirusTrojan.Win32.Bublik.cnetvt
EmsisoftTrojan.Downloader.Small.ABNE (B)
F-SecureTrojan.TR/AD.Yarwi.edcub
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Bublik.Win32.31007
TrendMicroTROJ_UPATRE.SMZ9
Trapminemalicious.high.ml.score
SophosMal/Packer
SentinelOneStatic AI – Malicious PE
GDataTrojan.Downloader.Small.ABNE
JiangminTrojan/Bublik.ged
WebrootTrojanproxy:Win32/Ranky.U
GoogleDetected
AviraTR/AD.Yarwi.edcub
VaristW32/SuspPack.DH.gen!Eldorado
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.Injector.KXE@5415yx
ArcabitTrojan.Downloader.Small.ABNE
ZoneAlarmTrojan.Win32.Bublik.bjqt
MicrosoftTrojan:Win32/Caynamer.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Bublik.R646211
BitDefenderThetaAI:Packer.101F0C841F
MAXmalware (ai score=89)
VBA32Trojan.Bublik
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderL
YandexTrojan.Bublik!EQCddiDKLx0
IkarusTrojan-Downloader.Win32.Small
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Waski.A!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Trojan.Downloader.Small.ABNE?

Trojan.Downloader.Small.ABNE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment