Malware

Win32/Small.NXM (file analysis)

Malware Removal

The Win32/Small.NXM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Small.NXM virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine Win32/Small.NXM?


File Info:

name: EEF6D5924B97D1786DD4.mlw
path: /opt/CAPEv2/storage/binaries/130d7564c3b6f52dfebebe7ed9a157cd92dc9867e86e365ede04610690d148ce
crc32: 54F319F4
md5: eef6d5924b97d1786dd48e24c308a52d
sha1: 1fa9c8f90c6961ff4c7abca6ce4b6be8327fab57
sha256: 130d7564c3b6f52dfebebe7ed9a157cd92dc9867e86e365ede04610690d148ce
sha512: a547c2f6a0a31d713a350c2ef68469a2bc583def192032157b4e306cbdf61e0bee2433b12a22699b0b75f6d34ddf5ff6293cae06b14e1a4457afe84ababc0084
ssdeep: 192:YgyLghwqzmTW1R7KOTYRHnhWgN7aoWry50Nr7OxX01k9z3AzslzLWh4G:YpghPzmYyHRN7Ay50ZSxR9zuslQN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2623ADBDA2CA483DE92BDF05298C983BC3D53D71640502B1297FE941DB37C39A2866D
sha3_384: 98726455d3012d90a4a06920891ec048e2a01cffb4d70e51a10e557beea6351017c718a28d978939e86bee728d29aef6
ep_bytes: 6a00e8e3030000a3163040006a60682e
timestamp: 2009-05-22 21:12:51

Version Info:

0: [No Data]

Win32/Small.NXM also known as:

MicroWorld-eScanTrojan.GenericKD.61823379
FireEyeGeneric.mg.eef6d5924b97d178
ALYacTrojan.GenericKD.61823379
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005962491 )
AlibabaTrojan:Win32/Generic.9ad059f3
K7GWTrojan ( 005962491 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Small.NXM
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderTrojan.GenericKD.61823379
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.FalseSign.Jjgl
Ad-AwareTrojan.GenericKD.61823379
SophosMal/Generic-S
ZillyaDownloader.Agent.Win32.121584
McAfee-GW-EditionRDN/Generic.dx
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.61823379 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.ACHDJW
JiangminTrojanDownloader.Agent.dlwq
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.13
ArcabitTrojan.Generic.D3AF5993
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Genome.C54311
McAfeeRDN/Generic.dx
MAXmalware (ai score=85)
VBA32Trojan.Casdet
TrendMicro-HouseCallTROJ_GEN.R002H0CI622
RisingTrojan.Occamy!8.F1CD (TFE:2:2NgNMBkwXcD)
YandexTrojan.GenAsa!82YmW6UjuFQ
IkarusTrojan.Win32.Small
FortinetW32/Small.NXM!tr
AVGWin32:Evo-gen [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Small.NXM?

Win32/Small.NXM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment