Malware

Win32/Small.NWG removal

Malware Removal

The Win32/Small.NWG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Small.NWG virus can do?

  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Win32/Small.NWG?


File Info:

name: C1A1E1946E0D750087E5.mlw
path: /opt/CAPEv2/storage/binaries/1ac7f4cee8b614359cb0997c1934e8b2e4cab0bbfddfa84bedb6d1b2f55e26f3
crc32: AC618904
md5: c1a1e1946e0d750087e57ac67a5c3ce4
sha1: da6cea0211746ad87ecdf58f6f32de8650cf4657
sha256: 1ac7f4cee8b614359cb0997c1934e8b2e4cab0bbfddfa84bedb6d1b2f55e26f3
sha512: f0867c3d21fefad0dc494c7d6914f70bf7abc6d3f3529d585a7b6779195c443500e8ef0096e29c9aef2bc10bf986004b49a57e75699460b840c695dfd78d06a4
ssdeep: 384:fSWgFGTNJET3NiyGkZNCMpRsQ7uV40IfXw0rh3vLAX1xq3UZU92psWmjSAy:bgcszsQIzoXwQpLALZU99I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16843D502AA014554F71C0B701906FAF549A9AD3D2AE8F69FF778BD7968312939CB310F
sha3_384: 8c8dfdc1d6c9a56dd9ebf14edc3cebcae6514741ca0063c919fb11564c4824d122d9ad70c2f1841e64856a714b121390
ep_bytes: e883040000e936fdffff8bff558bec81
timestamp: 2021-07-19 13:02:39

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Services
FileVersion: 30, 0, 9, 1
InternalName: winsc
LegalCopyright: Copyright (C) 2020
OriginalFilename: winsc.exe
ProductName: Services
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Win32/Small.NWG also known as:

LionicTrojan.Win32.APosT.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46749286
ALYacTrojan.APosT.gen
CylanceUnsafe
SangforTrojan.Win32.APosT.gen
K7AntiVirusTrojan ( 005808af1 )
AlibabaTrojan:Win32/APosT.1a1f2dd0
K7GWTrojan ( 005808af1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34726.du0@aeb9i7gi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Small.NWG
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.APosT.gen
BitDefenderTrojan.GenericKD.46749286
CynetMalicious (score: 100)
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.46749286
VIPRETrojan.GenericKD.46749286
FireEyeGeneric.mg.c1a1e1946e0d7500
EmsisoftTrojan.GenericKD.46749286 (B)
IkarusTrojan.Win32.Small
GDataTrojan.GenericKD.46749286
JiangminTrojan.APosT.asq
AviraHEUR/AGEN.1240591
ArcabitTrojan.Generic.D2C95666
ZoneAlarmHEUR:Trojan.Win32.APosT.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4605653
McAfeeArtemis!C1A1E1946E0D
MAXmalware (ai score=84)
VBA32BScope.Trojan.APosT
MalwarebytesTrojan.Dropper
RisingDownloader.[Bitter]Agent!1.DDB2 (CLASSIC)
YandexTrojan.APosT!R2tlpp+dG+M
MaxSecureTrojan.Malware.11910789.susgen
FortinetW32/Small.NWG!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Win32/Small.NWG?

Win32/Small.NWG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment