Trojan

Trojan.Win32.Small.cox removal

Malware Removal

The Trojan.Win32.Small.cox is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Small.cox virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Starts servers listening on 0.0.0.0:5434
  • Expresses interest in specific running processes
  • Installs a browser addon or extension
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Code injection with CreateRemoteThread in a remote process
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Operates on local firewall’s policies and settings
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to block SafeBoot use by removing registry keys
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

padrup.com.ds

How to determine Trojan.Win32.Small.cox?


File Info:

crc32: 59E64A5E
md5: fbb25f75ec93762e3874c1ab975ce4e3
name: FBB25F75EC93762E3874C1AB975CE4E3.mlw
sha1: bae96d41dc590c1ecdc451f3241e4b7a4ce108d2
sha256: fc795ff7a9da1eef9bf4b88124d70e3afa7e19b317ea9a96cc8ae448ade5b492
sha512: 6e698c4f555d6d9d2a23b16967ec46dc5bc17b7ffb4597a0b15abbe71b81f12f7bd64c29b211e31d8c74a794566a7c90a966796b0d988ffa0cce1123262fcfc4
ssdeep: 1536:dKMffw7pGW22ggMf7G/xZIYjHH+yb4NmaQDichCwPa0uCVbR:dNMpfRggMK/xZIOe44gaQ2KRPaXUR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Small.cox also known as:

BkavW32.Sality.PE
K7AntiVirusTrojan ( 001cddbb1 )
Elasticmalicious (high confidence)
DrWebWin32.Sector.22
CynetMalicious (score: 100)
CAT-QuickHealW32.Sality.U
ALYacTrojan.SalityStub.F
CylanceUnsafe
ZillyaTrojan.Sality.Win32.99
SangforVirus_Suspicious.Win32.Sality.bh
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 001cddbb1 )
Cybereasonmalicious.5ec937
BaiduWin32.Virus.Sality.gen
CyrenW32/Sality.gen2
SymantecW32.Sality.AE
ESET-NOD32Win32/Sality.NBA
APEXMalicious
AvastWin32:Sality [Inf]
ClamAVWin.Trojan.Small-5420
KasperskyTrojan.Win32.Small.cox
BitDefenderTrojan.SalityStub.F
NANO-AntivirusVirus.Win32.Sality.bzkem
ViRobotWin32.Sality.N.Host
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor
MicroWorld-eScanTrojan.SalityStub.F
TencentVirus.Win32.TuTu.Gen.200004
Ad-AwareTrojan.SalityStub.F
SophosML/PE-A + Troj/SalLoad-C
ComodoVirus.Win32.Sality.gen@1egj5j
BitDefenderThetaAI:FileInfector.A5ECCBAB0E
VIPREVirus.Win32.Sality.at!dam (v)
TrendMicroPE_SALITY.SM-O
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nc
FireEyeGeneric.mg.fbb25f75ec93762e
EmsisoftTrojan.SalityStub.F (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Small.oace.a
WebrootW32.Trojan.Gen
AviraW32/Sality.AT
Antiy-AVLTrojan/Generic.ASVirus.C4
MicrosoftVirus:Win32/Sality.AT
GDataTrojan.SalityStub.F
AhnLab-V3Win32/Kashu.E
Acronissuspicious
McAfeePWS-Zbot.gen.yh
MAXmalware (ai score=87)
VBA32Virus.Win32.Sality.bakb
MalwarebytesTrojan.Agent
PandaW32/Sality.AA
TrendMicro-HouseCallPE_SALITY.SM-O
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrKGmjK5di4nOqWVCQaQGBY)
YandexTrojan.GenAsa!5Tj45QuXiP0
IkarusTrojan.Win32.Salrenmetie
MaxSecureVirus.Sality.BH
FortinetW32/Agent.ABC!tr
AVGWin32:Sality [Inf]

How to remove Trojan.Win32.Small.cox?

Trojan.Win32.Small.cox removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment