Malware

Win32:Small-JVY [Trj] removal tips

Malware Removal

The Win32:Small-JVY [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Small-JVY [Trj] virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:Small-JVY [Trj]?


File Info:

name: CAD125DB69A5DEE68FA4.mlw
path: /opt/CAPEv2/storage/binaries/dc2587489197e9906a2b7b66220ecb36546070476b076934fd18d8bc0052cc0a
crc32: 72B91104
md5: cad125db69a5dee68fa44e48b3f4a6f1
sha1: 48ce7d35f59576a17109704f50a69abbaa51f51c
sha256: dc2587489197e9906a2b7b66220ecb36546070476b076934fd18d8bc0052cc0a
sha512: ed2b514d8df2ba4e61ff14d49c87d9961dd13da699e6ca37db688aee1fda00affd88f0c3558aa8c2841793cbc41c698b6a6f81e841f13cceb937eb23228bc8d5
ssdeep: 98304:i0qh0r0q2wf02GzMwDws0q40q0qC0FwwRZHwNwYwz0qm0S0qC0mR2wqEwE0qJ0nI:i7effIPEsy58doQaTzwZ8Jq3ELhf8cHR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1895623BAF31D6CA0FF3D4A77937CBA25C918FC525EB8F8AFB84D5A8521C1A55C852040
sha3_384: 12be8cfe9910e89b5b38854d9ebda434f3d3581625c179857322a87881062c71784164e1b454c8d8b78867903c750e7c
ep_bytes: 558bec6aff68b8fd4100686025420064
timestamp: 2008-03-14 10:18:02

Version Info:

0: [No Data]

Win32:Small-JVY [Trj] also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Crypt.AI
CAT-QuickHealTrojan.MauvaiseRI.S5244566
SkyhighBehavesLike.Win32.Generic.tc
McAfeeBackDoor-DRW
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Crypt.AI
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Downloader.Agent.au
VirITWorm.Win32.Socks.S
SymantecW32.SillyFDC
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Socks.NAL
APEXMalicious
TrendMicro-HouseCallWORM_SOCKS.EC
ClamAVWin.Worm.Socks-9
KasperskyWorm.Win32.Socks.pgf
BitDefenderTrojan.Crypt.AI
NANO-AntivirusTrojan.Win32.Pace.ihwkc
AvastWin32:Small-JVY [Trj]
EmsisoftTrojan.Crypt.AI (B)
F-SecureTrojan.TR/PSW.Agent.nhg
DrWebTrojan.PWS.Pace
ZillyaWorm.Socks.Win32.352
TrendMicroWORM_SOCKS.EC
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.cad125db69a5dee6
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
JiangminWorm/Socks.aa
WebrootW32.Worm.Socks.Gen
GoogleDetected
AviraTR/PSW.Agent.nhg
VaristW32/Socks.C.gen!Eldorado
Antiy-AVLWorm/Win32.Socks
MicrosoftBackdoor:Win32/Koceg!atmnm
XcitiumWorm.Win32.Agent.~CY@2v635
ArcabitTrojan.Crypt.AI
ZoneAlarmWorm.Win32.Socks.pgf
GDataWin32.Trojan.PSE.MRAPUC
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Socks.R2896
Acronissuspicious
VBA32BScope.TrojanDownloader.Small
ALYacTrojan.Crypt.AI
Cylanceunsafe
PandaTrj/Downloader.TCG
RisingTrojan.Agent!1.6618 (CLASSIC)
YandexTrojan.GenAsa!apPEMii4eOc
IkarusWorm.Win32.Socks
MaxSecureWorm.W32.Socks.S
FortinetW32/Socks.NAL!tr
BitDefenderThetaGen:NN.ZexaF.36744.@pZ@aKrgiRn
AVGWin32:Small-JVY [Trj]
Cybereasonmalicious.5f5957
DeepInstinctMALICIOUS

How to remove Win32:Small-JVY [Trj]?

Win32:Small-JVY [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment