Trojan

About “Win32/TrojanDownloader.Tiny.NPD” infection

Malware Removal

The Win32/TrojanDownloader.Tiny.NPD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Tiny.NPD virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/TrojanDownloader.Tiny.NPD?


File Info:

name: C2811AF1DAB84CA7F70E.mlw
path: /opt/CAPEv2/storage/binaries/27dd5a3466e4bade2238aa7f6d5cb7015110ceb10ba00c1769e4bc44fe80bcb8
crc32: 66426D82
md5: c2811af1dab84ca7f70ecd12dd0aa2b2
sha1: a2e13538f84d0dc0974dd70b43fd4f79ad978313
sha256: 27dd5a3466e4bade2238aa7f6d5cb7015110ceb10ba00c1769e4bc44fe80bcb8
sha512: 59e249b6e75626d590f343ba0884ab5c5a640ba8334c94bca94ca0724a7098c6852e0c3a5a6d4786ab0e912596f080983510e6ca50c10f9b9c4454542ee0ec1d
ssdeep: 24:nJl/X88lgQvxjn3hHqwtcWw+5X4YdQfHSg/3Ih7XszWrpno0aab5odjiBSBdt9N:r/88WwNKwtcWwkU2szopD2djiwBdx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B41B66716DA027EE18541B975E71327C0BC38EA4DA6D16D0320753538B6FCCB665E12
sha3_384: 98f7e5373accb3a97ad9ff1374a632084e54c385129c30ddadd2a37ce1a8db61e8b46af37ab883136da53ca64a85a050
ep_bytes: 535055eb526bed006bed0083c5009c57
timestamp: 2018-05-27 23:00:58

Version Info:

0: [No Data]

Win32/TrojanDownloader.Tiny.NPD also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
DrWebBackDoor.Remcos.1
MicroWorld-eScanGen:Trojan.Downloader.aeX@aO0hFan
FireEyeGeneric.mg.c2811af1dab84ca7
McAfeeGenericRXES-DB!C2811AF1DAB8
CylanceUnsafe
SangforTrojan.Win32.Skeeyah.A
K7AntiVirusTrojan-Downloader ( 0052aefa1 )
AlibabaTrojanDownloader:Win32/Skeeyah.e5bf218e
K7GWTrojan-Downloader ( 0052aefa1 )
Cybereasonmalicious.1dab84
BitDefenderThetaGen:NN.ZexaF.34742.aeX@aO0hFan
CyrenW32/TinyDownldr.A.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Tiny.NPD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Remcos-6656070-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.Downloader.aeX@aO0hFan
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Generic.Sxdx
Ad-AwareGen:Trojan.Downloader.aeX@aO0hFan
EmsisoftGen:Trojan.Downloader.aeX@aO0hFan (B)
ComodoMalware@#2z3skfri5ibqq
ZillyaDownloader.Tiny.Win32.11051
TrendMicroTrojan.Win32.TINY.A
McAfee-GW-EditionBehavesLike.Win32.Generic.xt
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Trojan.Downloader.aeX@aO0hFan
JiangminTrojanDownloader.Generic.azrv
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Skeeyah.A!bit
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2479955
Acronissuspicious
VBA32BScope.Backdoor.Remcos
ALYacBackdoor.Remcos.A
TrendMicro-HouseCallTrojan.Win32.TINY.A
RisingTrojan.Generic@AI.98 (RDML:4kBCev1yKlTtWJOQ5im7UQ)
YandexTrojan.DL.Tiny!MGYhArGXLeQ
IkarusTrojan-Downloader.Win32.Tiny
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.NPD!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/TrojanDownloader.Tiny.NPD?

Win32/TrojanDownloader.Tiny.NPD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment