Trojan

Should I remove “Win32/TrojanDownloader.Tiny.NTW”?

Malware Removal

The Win32/TrojanDownloader.Tiny.NTW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Tiny.NTW virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Fake User-Agent detected
  • Creates a hidden or system file
  • Attempts to modify proxy settings

How to determine Win32/TrojanDownloader.Tiny.NTW?


File Info:

name: 9D10B0891CCA66B62CDB.mlw
path: /opt/CAPEv2/storage/binaries/37aa7097e7428b2310ed37230165b2f928c5e4f3092df11f141a872cd7e737a2
crc32: 5E993AD5
md5: 9d10b0891cca66b62cdbd0b6ce06d6a7
sha1: 6be086391a592bb16dc4a0177317102fd8d326f7
sha256: 37aa7097e7428b2310ed37230165b2f928c5e4f3092df11f141a872cd7e737a2
sha512: e6c87d98e2ae0989da0d5b6d45100a2d85cd1255984f22433e9c6376122b68cff3d50816324c0399cf2ca41243400ac9d3bcf679ed16f068f9b6c10db0ef652d
ssdeep: 48:C9XenoHpw3w6lvynXBP+br3AVnaDAtboyl1AlinJCSCMdXg:XE6lvcPkUBa8tboynAUJCtMdw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173B1D65BBF050032C3760B312E1760A4EB6E027B071989DFBA2B01CD6705E9768773DA
sha3_384: b286c09cf5739ef13126d2bfeb6b211449d17e63799c3c003b9a607d404a394222f20062227d901b13e190f0e28e7c1f
ep_bytes: 558bec6aff685821400068b012400064
timestamp: 2021-12-06 06:43:52

Version Info:

0: [No Data]

Win32/TrojanDownloader.Tiny.NTW also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.403071
FireEyeGeneric.mg.9d10b0891cca66b6
ALYacGen:Variant.Zusy.403071
CylanceUnsafe
ZillyaDownloader.Tiny.Win32.22935
SangforTrojan.Win32.Badur.ky
K7AntiVirusTrojan-Downloader ( 0058bcfb1 )
AlibabaTrojanDownloader:Win32/Generic.70a2231a
K7GWTrojan-Downloader ( 0058bcfb1 )
Cybereasonmalicious.91a592
CyrenW32/Sabsik.Y.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Tiny.NTW
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.403071
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11de6781
EmsisoftGen:Variant.Zusy.403071 (B)
TrendMicroTROJ_GEN.R002C0WLF21
McAfee-GW-EditionBehavesLike.Win32.Generic.zz
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Badur.li
AviraHEUR/AGEN.1133614
Antiy-AVLTrojan/Generic.ASMalwS.34F0E55
MicrosoftTrojan:Win32/Mamson.A!ac
GDataGen:Variant.Zusy.403071
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R458753
McAfeeGenericRXAA-AA!9D10B0891CCA
MAXmalware (ai score=86)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R002C0WLF21
RisingDownloader.Tiny!8.245 (RDMK:cmRtazqxyY7Fb958U9k6Nel8GNlr)
IkarusTrojan-Downloader.Win32.Tiny
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZexaF.34182.auW@ayRfdcli
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/TrojanDownloader.Tiny.NTW?

Win32/TrojanDownloader.Tiny.NTW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment