Trojan

What is “Win32/TrojanDownloader.Small.POE”?

Malware Removal

The Win32/TrojanDownloader.Small.POE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Small.POE virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Win32/TrojanDownloader.Small.POE?


File Info:

name: E8B25C7EB206F91551D1.mlw
path: /opt/CAPEv2/storage/binaries/06af7cadee31e3067c685d89d26cb9f8f137e7cae1c6f2fe4c16420fc2ce46ff
crc32: D9C5CD36
md5: e8b25c7eb206f91551d144da6216b257
sha1: 23bdc0614ae9502fbdc27a2c37e19a6c2bb114f2
sha256: 06af7cadee31e3067c685d89d26cb9f8f137e7cae1c6f2fe4c16420fc2ce46ff
sha512: fcc0ba8e5d0c8c69fb5464df11df7ae8859a4876546a27acb965bac7c410fc0ceea30de6959054a073343c142657ab3b17c2493820627296192a2c278e0ffc10
ssdeep: 24576:Pe4nJCfODhkUfSDizU2lu8SESIyOMWUMrQO5pDKY8OsincU060t4:W4nJCfyhfSWo2luvIrMWUMMUJbW6u4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D3523266AE8903AE4F43A3003BE613097BDFC345734A36F469A15F695B2DD027B9317
sha3_384: ade2b37dee01ddaa2c5e9ae2be89b425323d3a5f7f102176f89440afa282680f21df640be3069e3c91792ff984ffb13f
ep_bytes: e80a000000e97affffffcccccccccc8b
timestamp: 2004-08-04 06:01:37

Version Info:

0: [No Data]

Win32/TrojanDownloader.Small.POE also known as:

LionicTrojan.Win32.Generic.a!c
MicroWorld-eScanGen:Heur.Crifi.1
FireEyeGeneric.mg.e8b25c7eb206f915
ALYacGen:Heur.Crifi.1
CylanceUnsafe
Cybereasonmalicious.eb206f
CyrenW32/Chifrax!Generic
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.POE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Genome.dvot
BitDefenderGen:Heur.Crifi.1
NANO-AntivirusTrojan.Win32.Small.rjklo
AvastWin32:Trojan-gen
Ad-AwareGen:Heur.Crifi.1
EmsisoftGen:Heur.Crifi.1 (B)
ComodoSuspicious@#3n3n2k6txhpad
F-SecureTrojan.TR/Dldr.Tiny.C
DrWebTrojan.Packed.1726
VIPREGen:Heur.Crifi.1
TrendMicroTROJ_GEN.R002C0DK221
McAfee-GW-EditionArtemis!Trojan
SophosGeneric ML PUA (PUA)
GDataGen:Heur.Crifi.1
JiangminTrojan/Small.fcb
AviraTR/Dldr.Tiny.C
Antiy-AVLTrojan/Generic.ASMalwS.151
KingsoftWin32.Heur.KVM017.a.(kcloud)
ArcabitTrojan.Crifi.1
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
McAfeeArtemis!E8B25C7EB206
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
TrendMicro-HouseCallTROJ_GEN.R002C0DK221
RisingDownloader.Genome!8.142 (TFE:5:Y9Xr5xMMyUL)
YandexTrojan.GenAsa!677k6lubAaw
IkarusTrojan.Win32.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Scribble.B
BitDefenderThetaAI:Packer.089CAEF923
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Win32/TrojanDownloader.Small.POE?

Win32/TrojanDownloader.Small.POE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment