Malware

About “MSIL/Agent.SMM” infection

Malware Removal

The MSIL/Agent.SMM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.SMM virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/Agent.SMM?


File Info:

crc32: FB3287BA
md5: 5a1338ed06e2f7e75b5910d4685dc902
name: 5A1338ED06E2F7E75B5910D4685DC902.mlw
sha1: 7755317123aee1d6a56febd92ab2196775f0eafd
sha256: d1a94e84fbcfbedb9543dfb0e8551b246815fcb3209f7c7eee74b24bf6af33a5
sha512: ca50c1b88282e85d7d36ad7e32eda336041b76ff4fa0c6d789fcabe12561fb3d7d8b1ac1a734117fb791a4ba397d133ae050b23b2e011438a637e0a888cd41e8
ssdeep: 96:0IqyUZI30SCMXW7CDAjJvfB2y+y+NGR0oROIwJiGdlbGe8EC6ixykpMtyD2L1WS:0IqyYvfwy+EOIaBlbP/pixm1pWxU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2018
Assembly Version: 1.0.0.0
InternalName: KeyRedirEx.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: KeyRedirEx
ProductVersion: 1.0.0.0
FileDescription: KeyRedirEx
OriginalFilename: KeyRedirEx.exe

MSIL/Agent.SMM also known as:

K7AntiVirusTrojan ( 0052dc5f1 )
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Johnnie.119264
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:MSIL/ClipBanker.ac18c193
K7GWTrojan ( 0052dc5f1 )
Cybereasonmalicious.d06e2f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.SMM
AvastWin32:Malware-gen
KasperskyTrojan-Banker.MSIL.ClipBanker.c
BitDefenderGen:Variant.Johnnie.119264
NANO-AntivirusTrojan.Win32.Razy.faxyvf
MicroWorld-eScanGen:Variant.Johnnie.119264
TencentMsil.Trojan-banker.Clipbanker.Suxn
Ad-AwareGen:Variant.Johnnie.119264
SophosMal/Generic-S
ComodoMalware@#2666f9j0dcqpn
BitDefenderThetaGen:NN.ZemsilF.34142.am0@aKoa@5b
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GG921
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.5a1338ed06e2f7e7
EmsisoftGen:Variant.Johnnie.119264 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Agent.saslu
eGambitUnsafe.AI_Score_84%
MicrosoftTrojan:Win32/Tiggre!rfn
SUPERAntiSpywareTrojan.Agent/Gen-ClipBanker
ZoneAlarmTrojan-Banker.MSIL.ClipBanker.c
GDataGen:Variant.Johnnie.119264
AhnLab-V3Trojan/Win32.Tiggre.C2550041
McAfeeArtemis!5A1338ED06E2
MAXmalware (ai score=94)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.ClipBanker
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0GG921
YandexTrojan.Agent!esSvUdec5uE
IkarusTrojan.MSIL.Agent
FortinetMSIL/Generic.AP.E781763!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Agent.SMM?

MSIL/Agent.SMM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment