Trojan

How to remove “Trojan.Win32.Small.acli”?

Malware Removal

The Trojan.Win32.Small.acli is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Small.acli virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Starts servers listening on 0.0.0.0:3159
  • Drops a binary and executes it
  • Performs some HTTP requests
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
shwpehrprn.biz
rwereqhssn.org
ma1-aaemail-dr-lapp01.apple.com
ma1-aaemail-dr-lapp02.apple.com
ma1-aaemail-dr-lapp03.apple.com
rn-mailsvcp-ppex-lapp14.apple.com
rn-mailsvcp-ppex-lapp15.apple.com
spephnhrpa.biz
rn-mailsvcp-ppex-lapp24.apple.com
mx01.oxsus-vadesecure.net
rn-mailsvcp-ppex-lapp34.apple.com
mxb-00377f03.gslb.pphosted.com
rn-mailsvcp-ppex-lapp35.apple.com
mx02.oxsus-vadesecure.net
rn-mailsvcp-ppex-lapp44.apple.com
mxb-00377f01.gslb.pphosted.com
rn-mailsvcp-ppex-lapp45.apple.com
rrwwweemqs.org
mx03.oxsus-vadesecure.net
mx04.oxsus-vadesecure.net
mx.cam.ac.uk
ismtp.sitestar.everyone.net
onlineconnections.com.au
mx2-lw-eu.apache.org
mx2-lw-us.apache.org
mx1-lw-eu.apache.org
mx1-lw-us.apache.org
mxbiz1.qq.com
mxbiz2.qq.com
digicool.com
mail.python.org
in2-smtp.messagingengine.com

How to determine Trojan.Win32.Small.acli?


File Info:

crc32: E76905E0
md5: d331a53d6deced27e44a1b23a897c660
name: D331A53D6DECED27E44A1B23A897C660.mlw
sha1: a96d6f7f562943794a632b7071c2bc228477ed6f
sha256: 29051e0cdfd29405d4766b2d09e93c03b190fc71d094d11fb0e7bc998187689d
sha512: 632b1a37d395a9dad7e2ac1c47007b98c877f187ecf564935fa1cb9062ceed13eacd98cc9782e815d616c204e38e9c3bef43f4223c3f69a4b94562e899543a18
ssdeep: 3072:pOjWuyt0ZsqsXOKofHfHTXQLzgvnzHPowYbvrjD/L7QPbg/Dr0T3rnXLHf7zjPP:pIs9OKofHfHTXQLzgvnzHPowYbvrjD/
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Small.acli also known as:

BkavW32.AIDetectVM.malware1
K7AntiVirusTrojan ( 004d7c651 )
DrWebTrojan.DownLoader8.56532
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Small.S5091480
ALYacTrojan.GenericKDZ.66635
CylanceUnsafe
ZillyaDropper.Mudrop.Win32.4765
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Small.b09fa102
K7GWTrojan ( 004d7c651 )
Cybereasonmalicious.d6dece
TrendMicroTROJ_GEN.R002C0DE620
CyrenW32/S-e4365596!Eldorado
SymantecW32.Mydoom.B@mm
ESET-NOD32a variant of Win32/Agent.NHB
APEXMalicious
AvastWin32:Mydoom-BJ [Wrm]
ClamAVWin.Dropper.Mudrop-6801241-0
KasperskyTrojan.Win32.Small.acli
BitDefenderTrojan.GenericKDZ.66635
NANO-AntivirusTrojan.Win32.Mudrop.ijmve
ViRobotTrojan.Win32.Z.Mydoom.121440.EC
SUPERAntiSpywareTrojan.Agent/Gen-MalPE
MicroWorld-eScanTrojan.GenericKDZ.66635
TencentMalware.Win32.Gencirc.10b0c1b8
Ad-AwareTrojan.GenericKDZ.66635
SophosMal/Behav-104
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Proxy.Gen
BitDefenderThetaAI:Packer.3BF5C8131D
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
FireEyeGeneric.mg.d331a53d6deced27
EmsisoftTrojan.GenericKDZ.66635 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/S-e4365596!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Downloader.Gen
AviraTR/Proxy.Gen
Antiy-AVLTrojan[Dropper]/Win32.Mudrop
MicrosoftTrojan:Win32/Mydoom
JiangminTrojanDropper.Mudrop.bpo
ArcabitTrojan.Generic.D1044B
AegisLabTrojan.Win32.Small.tpLR
ZoneAlarmTrojan.Win32.Small.acli
GDataTrojan.GenericKDZ.66635
TACHYONTrojan-Dropper/W32.Agent.121440
AhnLab-V3Dropper/Win32.Mudrop.C84237
Acronissuspicious
McAfeeW32/Mytob.gen@MM.i
MAXmalware (ai score=83)
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesWorm.MyDoom
PandaW32/MyDoom.IC.worm
TrendMicro-HouseCallTROJ_GEN.R002C0DE620
RisingTrojan.Agent!1.C364 (CLOUD)
YandexTrojan.Small!WXyRwxTa7/U
IkarusTrojan.Win32.Mydoom
eGambitUnsafe.AI_Score_100%
FortinetW32/Agent.NHB!worm
AVGWin32:Mydoom-BJ [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.8e6

How to remove Trojan.Win32.Small.acli?

Trojan.Win32.Small.acli removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment