Trojan

TrojanDownloader:Win32/Small information

Malware Removal

The TrojanDownloader:Win32/Small is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Small virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Created a service that was not started
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

update.kuai-go.com
usa.kuai-go.com
korea.kuai-go.com
fwq.kuai-go.com

How to determine TrojanDownloader:Win32/Small?


File Info:

crc32: F3A0864D
md5: 339bec2b3e598b98218c16ed1e762b2a
name: n.exe
sha1: 001a4bb41655c17eca6921420af00bb36fdc0922
sha256: 51b3d6b1add70e3b14c8ea224dd804467523a4fe2360021576f559761331a084
sha512: f0e53e38169e68856d3cd326c12e7f6174b169f6780fb1c5c81db94cf3c0b3bb47654415099f83ee8ccee119e6609306e1867777c8688857bae4346f181e1e25
ssdeep: 3072:GcD/8FOh8v1VWznIFfqdETVP19F5tEB3N8Ns0Fb8xESsfxjoV:GKlSdVsnAfS61jEdWNFCtsJC
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Microsoft Windows Operating System
InternalName: Microsoft Windows Operating System
FileVersion: 2.1.0.0
CompanyName: Microsoft Windows Operating System
LegalTrademarks: Microsoft Windows Operating System
Comments: Microsoft Windows Operating System
ProductName: Microsoft
ProductVersion: 1.0.0.0
FileDescription: Microsoft Windows Operating System
OriginalFilename: Microsoft
Translation: 0x0809 0x04e4

TrojanDownloader:Win32/Small also known as:

DrWebTrojan.DownLoader23.39271
MicroWorld-eScanTrojan.GenericKD.41267737
FireEyeTrojan.GenericKD.41267737
CAT-QuickHealTrojan.Generic
McAfeeRDN/Generic.hbg
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005376ae1 )
BitDefenderTrojan.GenericKD.41267737
K7GWTrojan ( 005376ae1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTrojan.Win32.ZEGOST.B
BitDefenderThetaAI:Packer.37A5E3DF1C
F-ProtW32/SysVenFak.A.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.41267737
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDownloader:Win32/Skeeyah.7f23767b
NANO-AntivirusTrojan.Win32.Webmoner.elfdg
ViRobotTrojan.Win32.Z.Agent.149052
AegisLabTrojan.Win32.Malicious.4!c
Endgamemalicious (high confidence)
SophosMal/Behav-398
ComodoTrojWare.Win32.Spy.Banker.Gen@1qlojk
F-SecureTrojan.TR/Dldr.Agent.olsko
ZillyaDownloader.Delf.Win32.57578
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Virut.cc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.41334844 (B)
IkarusTrojan-Downloader.Win32.Dadobra
CyrenW32/Threat-SysVenFak-based!Maxi
JiangminTrojan.Generic.dmfkw
WebrootW32.Trojan.Gen
AviraTR/Dldr.Agent.olsko
MAXmalware (ai score=100)
MicrosoftTrojanDownloader:Win32/Small
ArcabitTrojan.Generic.D275B219
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Agent.R263235
Acronissuspicious
VBA32suspected of Trojan.Downloader.gen.h
ALYacTrojan.Downloader.Small
Ad-AwareTrojan.GenericKD.41267737
MalwarebytesTrojan.Injector
PandaTrj/CI.A
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.CJD
TrendMicro-HouseCallTrojan.Win32.ZEGOST.B
YandexTrojan.Agent!0KflZMsdvzw
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Skeeyah.F599!tr
AVGWin32:Malware-gen
Cybereasonmalicious.b3e598
Paloaltogeneric.ml
Qihoo-360HEUR/QVM17.0.1905.Malware.Gen

How to remove TrojanDownloader:Win32/Small?

TrojanDownloader:Win32/Small removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment