Crack

Should I remove “HackTool:MSIL/SmbAgent!atmn”?

Malware Removal

The HackTool:MSIL/SmbAgent!atmn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:MSIL/SmbAgent!atmn virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine HackTool:MSIL/SmbAgent!atmn?


File Info:

name: D420B3E3AF2230BCA262.mlw
path: /opt/CAPEv2/storage/binaries/c2ea6b04fe29f0b6b16bc7cb8a24443de01d5934b95fe9a78b814fdea051d5d0
crc32: 45080543
md5: d420b3e3af2230bca262265ad414db0f
sha1: a521a08a06ee46c6786edcae97b913b076ad9c18
sha256: c2ea6b04fe29f0b6b16bc7cb8a24443de01d5934b95fe9a78b814fdea051d5d0
sha512: fb8dac751d4f7f80d8c393f3a81ab5e2aa063106116d29875f02f7006af64ca1ffb701447847e9adf1d9cd89b8fe611b0f23e644c5b86202b9522c0e0dc4a413
ssdeep: 96:0H+lj9YDhx/cHyTqc8AU7y0Lz88JP44OBOpobqw9YM9K:0HQYb/Zu1ym88JpdkW
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A5C1E889BBD40E53F83A07795E73932957B4FD529E535B9F082016346C51B902E71BF0
sha3_384: 519be142527289c27b642c3dc9a04123a6e71a60c08eede2e993c94fc3d4741e44b95a694c3172651e8f55029ddd9ab8
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-01-10 19:52:44

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: 6nv1mys-.dll
LegalCopyright:
OriginalFilename: 6nv1mys-.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

HackTool:MSIL/SmbAgent!atmn also known as:

BkavW32.AIDetectMalware.CS
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.WX.986CFB2D
ClamAVWin.Malware.Smbagent-9769162-0
SkyhighBehavesLike.Win32.Agent.xt
McAfeeAgent-SMB.b!D420B3E3AF22
Cylanceunsafe
ZillyaTool.Agent.Win32.50896
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005962b21 )
K7GWTrojan ( 005962b21 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitGeneric.Malware.WX.986CFB2D
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/HackTool.Agent.BW potentially unsafe
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:HackTool.MSIL.SMBScan.gen
BitDefenderGeneric.Malware.WX.986CFB2D
NANO-AntivirusTrojan.Win32.Ric.ezglxv
AvastWin32:HacktoolX-gen [Trj]
TencentHackTool.MSIL.SmbScan.ha
EmsisoftGeneric.Malware.WX.986CFB2D (B)
DrWebTrojan.Siggen7.34567
VIPREGeneric.Malware.WX.986CFB2D
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminHackTool.MSIL.mdj
Antiy-AVLTrojan/Win32.Generic
Kingsoftmalware.kb.c.835
XcitiumTrojWare.MSIL.HackTool.Agent.ASD@8sg90t
MicrosoftHackTool:MSIL/SmbAgent!atmn
ZoneAlarmHEUR:HackTool.MSIL.SMBScan.gen
GDataMSIL.Riskware.SMBScanner.A
VaristW32/Hacktool.J.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R424570
TACHYONTrojan/W32.DN-SMBScan.6144
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
IkarusPUA.Hacktool.SMBAgent
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/HackTool
AVGWin32:HacktoolX-gen [Trj]
DeepInstinctMALICIOUS

How to remove HackTool:MSIL/SmbAgent!atmn?

HackTool:MSIL/SmbAgent!atmn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment