Malware

Win32/PSW.Small.NBE information

Malware Removal

The Win32/PSW.Small.NBE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Small.NBE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/PSW.Small.NBE?


File Info:

name: 36C9ECF822FAE272CE83.mlw
path: /opt/CAPEv2/storage/binaries/1639a26a598074885dc08393fd8177f171a5f321c3e5f061747a238caab49bbb
crc32: 302957CE
md5: 36c9ecf822fae272ce83a25e64ec2afc
sha1: 657eb2330fa8048a0ad0afc17fe7af755520c9ee
sha256: 1639a26a598074885dc08393fd8177f171a5f321c3e5f061747a238caab49bbb
sha512: 211238da0a9a462ae93d7c9e9dc0c28c54b9319a236b9d6abed6385778c541da0882880e0c484b62ad9fb479897898f89c7d6376a57d36527d103445cf548d53
ssdeep: 3072:UUL3W+t6Q3MK4wsd6Q8aN89lYTKY6fpcD5NjVUjoZlNEhNb8R7Duuvf9lNDirtlX:nx6fEhSB6fpc9Np+ox0adHirPPoen
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C544F1667FD089AFC0BA02301A19F4269C7665144E21EEF73FF4572FA8318D8C926D93
sha3_384: 9ba501a8fb8b35a6ff5b40b9a96de0580d8fbec3ea2e4877df09131ffd9cbe0d101e2c0a035f6823ab64dba7c59a3d0a
ep_bytes: f30f10c09090f30f10c08d6c01008b45
timestamp: 2009-11-01 13:57:56

Version Info:

0: [No Data]

Win32/PSW.Small.NBE also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.lrr0
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Generic.qmZ@ai3Iighb
FireEyeGeneric.mg.36c9ecf822fae272
SkyhighBehavesLike.Win32.RAHack.dc
ALYacGen:Trojan.Generic.qmZ@ai3Iighb
Cylanceunsafe
VIPREGen:Trojan.Generic.qmZ@ai3Iighb
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005662d91 )
BitDefenderGen:Trojan.Generic.qmZ@ai3Iighb
K7GWTrojan ( 005662d91 )
Cybereasonmalicious.30fa80
VirITTrojan.Win32.SHeur2.BPNN
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Small.NBE
APEXMalicious
ClamAVWin.Trojan.Dogrobot-331
KasperskyTrojan-Dropper.Win32.Agent.bjnu
AlibabaTrojanDropper:Win32/Nemqe.b23d2f5f
NANO-AntivirusTrojan.Win32.HLLW.bbkngk
RisingTrojan.Agent!1.67D1 (CLASSIC)
SophosMal/Generic-R
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.MulDrop.65194
ZillyaTrojan.Agent2.Win32.5106
TrendMicroTROJ_NEMQE.F
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Generic.qmZ@ai3Iighb (B)
IkarusTrojan-Downloader.Win32.Banload
MAXmalware (ai score=99)
JiangminHeur:Trojan/AntiHeur
GoogleDetected
AviraTR/Crypt.ULPM.Gen
VaristW32/Risk.MLJT-8035
Antiy-AVLTrojan[Dropper]/Win32.Agent
KingsoftWin32.HeurC.KVMH015.a
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumMalware@#20kncf7wr2hyy
ArcabitTrojan.Generic.EAD3AB
ZoneAlarmTrojan-Dropper.Win32.Agent.bjnu
GDataGen:Trojan.Generic.qmZ@ai3Iighb
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MMM.C11865
McAfeeArtemis!36C9ECF822FA
DeepInstinctMALICIOUS
VBA32TrojanPSW.OnLineGames.a
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_NEMQE.F
YandexTrojan.Agent2!1Hv//7Dl91w
SentinelOneStatic AI – Malicious PE
FortinetW32/Small.NBE!tr
BitDefenderThetaAI:Packer.43E6A14B20
AVGWin32:Dogrobot [Drp]
AvastWin32:Dogrobot [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/PSW.Small.NBE?

Win32/PSW.Small.NBE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment