Trojan

Win32/TrojanClicker.Small.NDF malicious file

Malware Removal

The Win32/TrojanClicker.Small.NDF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanClicker.Small.NDF virus can do?

  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/TrojanClicker.Small.NDF?


File Info:

name: A7F688FA3636AD2FCAE2.mlw
path: /opt/CAPEv2/storage/binaries/1f7b186a9f01d4b568ea919d5e215b634b1ebf1f6c32b5cbc83a3e735e91949f
crc32: 375BFB59
md5: a7f688fa3636ad2fcae26c9611c6a190
sha1: aa88813c30db05ae3c32c8ee4199f9321749e25d
sha256: 1f7b186a9f01d4b568ea919d5e215b634b1ebf1f6c32b5cbc83a3e735e91949f
sha512: b1ded61a0a6928ee921e9f90c3249b2acd573af130d9b96c727bff7fcba1bffabba2c04e57e1ef34e7a47085213e7ed5c42294514a217f82d2f2c95e45064bf0
ssdeep: 1536:DQEofGE6AlUwoG/su13qClQX2oooD+AyxArwIVJ9dMNYR:DQxGELUxu1a8QXMmwI/wYR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D783F243EF446E1AF43989745897C6E65E3ADE6CCCA5CA718480FC530C762AB253F319
sha3_384: c1a4640cb5bfa654ba09bccd2a1fa32b29b330fc6ca0d28bbe9beba2175819bb4e670d3fa1e71afecb8e727dc6b84040
ep_bytes: 60e8b70000002e400200000000000000
timestamp: 2014-01-07 11:49:58

Version Info:

Comments:
CompanyName:
FileDescription: Microsoft(R) Windows(R) Operating System
FileVersion: 6, 0, 2900, 5512
InternalName:
LegalCopyright: 版权所有 (C) 2013
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: Microsoft
ProductVersion: 6.00.2900.5512
SpecialBuild:
Translation: 0x0804 0x04b0

Win32/TrojanClicker.Small.NDF also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Llac.le6i
MicroWorld-eScanGen:Trojan.Heur.fu0@rHtl2Kcbh
ClamAVWin.Trojan.Agent-1364161
FireEyeGeneric.mg.a7f688fa3636ad2f
CAT-QuickHealTrojan.Llac.A.mue
SkyhighBehavesLike.Win32.Infected.mh
McAfeePacked-AK!A7F688FA3636
Cylanceunsafe
ZillyaTrojan.Llac.Win32.45571
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f7fd1 )
AlibabaBackdoor:Win32/Emager.ab5e4ac3
K7GWTrojan ( 0040f7fd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.9A34A0091D
VirITTrojan.Win32.Generic.BQPU
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanClicker.Small.NDF
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Emager.ngb
BitDefenderGen:Trojan.Heur.fu0@rHtl2Kcbh
NANO-AntivirusTrojan.Win32.FKM.dsobxk
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Dropper.abe
EmsisoftGen:Trojan.Heur.fu0@rHtl2Kcbh (B)
BaiduWin32.Trojan.Kryptik.av
F-SecureTrojan.TR/Crypt.FKM.Gen
DrWebTrojan.Siggen6.14220
VIPREGen:Trojan.Heur.fu0@rHtl2Kcbh
TrendMicroTROJ_GEN.R002C0DB324
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.TrojanClicker
GDataGen:Trojan.Heur.fu0@rHtl2Kcbh
JiangminTrojan.Emager.aoh
WebrootW32.Malware.gen
GoogleDetected
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan/Win32.Llac
Kingsoftmalware.kb.a.997
XcitiumTrojWare.Win32.BHO.NJYY@56oayy
ArcabitTrojan.Heur.EB47EA
ViRobotTrojan.Win.Z.Llac.86016.CS
ZoneAlarmTrojan.Win32.Emager.ngb
MicrosoftBackdoor:Win32/Dusenr.A
VaristW32/Cnezz.A.gen!Eldorado
AhnLab-V3Trojan/Win32.ADH.C116687
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Trojan.Heur.fu0@rHtl2Kcbh
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DB324
RisingBackdoor.Dusenr!1.A20B (CLASSIC)
YandexTrojan.Llac!G/z4jXWLeEQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7016547.susgen
FortinetW32/Agent.AGDA!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.c30db0
DeepInstinctMALICIOUS

How to remove Win32/TrojanClicker.Small.NDF?

Win32/TrojanClicker.Small.NDF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment