Trojan

Win32/TrojanDownloader.Small.PIC removal guide

Malware Removal

The Win32/TrojanDownloader.Small.PIC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Small.PIC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/TrojanDownloader.Small.PIC?


File Info:

name: 3104769F084F2DB0FD51.mlw
path: /opt/CAPEv2/storage/binaries/41375131ef42f9a0df178f36774afa8f89704b8633d842363173caa6f1bd699e
crc32: 2192DD90
md5: 3104769f084f2db0fd51d2d15a33cdbd
sha1: 0ac6d1acaeddfc14f27d6b2df1006b7db8b9e021
sha256: 41375131ef42f9a0df178f36774afa8f89704b8633d842363173caa6f1bd699e
sha512: 4de6f33b816acc6e04bab11ec5ff3bd4b47246e48fafd78f17b329fa0d5078d7b5f1b51ef60ef7eb8bfd76323e3b983c04184c59115ed95d2f8d36bb836eb1c1
ssdeep: 192:bcz2T/15e1Zd5fZGRLbv88xyWhrqCsbg4s9voRWe1R3dMEPxwx4SBI0qO6vv+Kez:Aa/gshOmqRXshi1RGwKIf3+pys
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150722AC6A90E9426C77603B148EB6A2510FDE570478861C3AFC1BFDDDFA11D19BF2422
sha3_384: d39ca7a2035c4508b15805657b6941ce1024ca40a1af49a146870a519a9a44cd1a2a79c98dd06acbc28551099ca3646b
ep_bytes: 558bec81ec74010000c785e4feffff00
timestamp: 2011-11-22 15:50:59

Version Info:

0: [No Data]

Win32/TrojanDownloader.Small.PIC also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Boigy.1
FireEyeGeneric.mg.3104769f084f2db0
CAT-QuickHealTrojan.Karagany.G
ALYacGen:Variant.Boigy.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Generic.AIG
CyrenW32/Karagany.J.gen!Eldorado
SymantecPacked.Generic.345
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PIC
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderGen:Variant.Boigy.1
NANO-AntivirusTrojan.Win32.Krap.wcwek
Ad-AwareGen:Variant.Boigy.1
ComodoTrojWare.Win32.Kazy.FOF@4pekmj
ZillyaDownloader.Small.Win32.45628
TrendMicroTROJ_KGANY.SMT
McAfee-GW-EditionPWS-Zbot.gen.bex
SophosTroj/Karagany-M
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.qscm
WebrootW32.Trojan.Gen
AviraTR/Karagany.gnamb
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GoogleDetected
AhnLab-V3Trojan/Win32.Injector.R15830
McAfeePWS-Zbot.gen.bex
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_KGANY.SMT
YandexTrojan.GenAsa!9sxDK9+Uh1s
TACHYONTrojan/W32.Krap.16896.HU
MaxSecureTrojan.Packed.Krap.iu
FortinetW32/Kryptik.DLD!tr
Cybereasonmalicious.f084f2
PandaBck/Qbot.AO

How to remove Win32/TrojanDownloader.Small.PIC?

Win32/TrojanDownloader.Small.PIC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment