Crack

What is “HackTool:MSIL/SmbAgent!atmn”?

Malware Removal

The HackTool:MSIL/SmbAgent!atmn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:MSIL/SmbAgent!atmn virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine HackTool:MSIL/SmbAgent!atmn?


File Info:

name: 17F8F41EF3B430CAADF1.mlw
path: /opt/CAPEv2/storage/binaries/076f572be90fc373426868f3bd11dfc89d28798c21a424db7c6edcca2dde39ce
crc32: 55206C65
md5: 17f8f41ef3b430caadf16026caa09155
sha1: 15e7462f546be170e438151057d21f3a48abd3f8
sha256: 076f572be90fc373426868f3bd11dfc89d28798c21a424db7c6edcca2dde39ce
sha512: dff7df7414319060aaec9fc9ad6dd6467e6dedfacbce165ddb0ce6b8a6f75ae9228c0825d8debeb7862dbe7bd4122d6d1203a217a439dbb6120c839029292877
ssdeep: 96:ZH+lj9YDhx/cHyTqc8AUbCC+Arz88stOOBOJob5w9YkFK:ZHQYb/ZuF2A88sqCka
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T150D1D58ABBD40E57E83A07746D73932A5B74F9429EA35B9F082012302E51B901F71BF0
sha3_384: 4991bfc529c8275198d5242690083a736155b81835c3408e85fe72329ad5a42eecfac40c3496a3a7983fbb6a938a5e24
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-02-21 14:11:42

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: l2rcjcs0.dll
LegalCopyright:
OriginalFilename: l2rcjcs0.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

HackTool:MSIL/SmbAgent!atmn also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.WX.AB15848E
ClamAVWin.Malware.Smbagent-9769162-0
CAT-QuickHealTrojan.GenericFC.S2479216
SkyhighBehavesLike.Win32.Agent.xt
McAfeeAgent-SMB.b!17F8F41EF3B4
MalwarebytesTrojan.Crypt
VIPREGeneric.Malware.WX.AB15848E
SangforSuspicious.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (W)
K7GWTrojan ( 005962b21 )
K7AntiVirusTrojan ( 005962b21 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/HackTool.Agent.BW potentially unsafe
APEXMalicious
KasperskyHEUR:HackTool.MSIL.SMBScan.gen
BitDefenderGeneric.Malware.WX.AB15848E
NANO-AntivirusTrojan.Win32.Ric.ezglxv
AvastWin32:HacktoolX-gen [Trj]
TencentHackTool.MSIL.SmbScan.ha
EmsisoftGeneric.Malware.WX.AB15848E (B)
DrWebTrojan.Siggen7.34567
FireEyeGeneric.mg.17f8f41ef3b430ca
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataMSIL.Riskware.SMBScanner.A
GoogleDetected
MAXmalware (ai score=89)
Antiy-AVLHackTool/Win32.Agent.a
Kingsoftmalware.kb.c.997
XcitiumTrojWare.MSIL.HackTool.Agent.ASD@8sg90t
ArcabitGeneric.Malware.WX.ABD3DE8E
ZoneAlarmHEUR:HackTool.MSIL.SMBScan.gen
MicrosoftHackTool:MSIL/SmbAgent!atmn
VaristW32/Hacktool.J.gen!Eldorado
AhnLab-V3Unwanted/Win32.HackTool.R261573
ALYacGeneric.Malware.WX.AB15848E
PandaTrj/GdSda.A
IkarusHackTool.MSIL.SMBScan
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/HackTool
AVGWin32:HacktoolX-gen [Trj]
DeepInstinctMALICIOUS

How to remove HackTool:MSIL/SmbAgent!atmn?

HackTool:MSIL/SmbAgent!atmn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment