Trojan

TrojanDownloader:Win32/SmallAgent.AW!MTB (file analysis)

Malware Removal

The TrojanDownloader:Win32/SmallAgent.AW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/SmallAgent.AW!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary

How to determine TrojanDownloader:Win32/SmallAgent.AW!MTB?


File Info:

name: 8CB953B35D754B701CB9.mlw
path: /opt/CAPEv2/storage/binaries/c2766a8328154a9e4b4343a446d632e5009d6570b140ffe8a0795f612584b7ec
crc32: B0C218CD
md5: 8cb953b35d754b701cb9885566180ba1
sha1: 16c1958000e0c219ed8e99945ec1fc90ed83edde
sha256: c2766a8328154a9e4b4343a446d632e5009d6570b140ffe8a0795f612584b7ec
sha512: 8543b35da5291b5c3bf35be858d006e152d58fb4fa16b200d5e3dbb67e858f114708ce33a0df54c27396f2e8edec2fd4757843749b45974b580fcf27a8d2f7fd
ssdeep: 12288:GREa3p8yg473H0DudXezE09Si/ckGHt6pshsPSGkYl2XIQCb+Lk1TWbPXQnAN5L:5O73UgXe4i7ojhsP5Lgrk1TWb4AN5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B65012277D280A5F1F7277065F48A619A3ABD726E34C99F7398111E0AB4ED0D934B33
sha3_384: 653bb985be4fd7b8d4bc7f98329c5073ca27540c46d49b4fd171b56419d326d0ced1de007a4236caa38fc27379689f35
ep_bytes: 3d70090000751d7d641e67a65bd2a269
timestamp: 2016-06-12 17:28:07

Version Info:

CompanyName: Sysinternals - www.sysinternals.com
FileDescription: NTFS Information Dump
FileVersion: 1.2
InternalName: NtfsInfo
LegalCopyright: Copyright (C) 2005-2016 Mark Russinovich
OriginalFilename: NtfsInfo.exe
ProductName: Sysinternals NtfsInfo
ProductVersion: 1.2
Translation: 0x0409 0x04b0

TrojanDownloader:Win32/SmallAgent.AW!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.8cb953b35d754b70
ALYacWin32.Expiro.Gen.7
CylanceUnsafe
BitDefenderWin32.Expiro.Gen.7
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.34212.yv0@aaaFL5di
CyrenW32/Expiro.AR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDP
KasperskyHEUR:Trojan-Downloader.Win32.BadOffer.gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingMalware.Heuristic!ET#87% (RDMK:cmRtazrDQ8qikT4CvJ/Oad0OeAb0)
Ad-AwareWin32.Expiro.Gen.7
SophosMal/Generic-S
DrWebWin32.Expiro.153
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
EmsisoftWin32.Expiro.Gen.7 (B)
APEXMalicious
GDataWin32.Expiro.Gen.7
JiangminTrojanDownloader.BadOffer.at
Antiy-AVLTrojan/Generic.ASVirus.316
MicrosoftTrojanDownloader:Win32/SmallAgent.AW!MTB
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win.SmallAgent.C4714498
McAfeeArtemis!8CB953B35D75
MAXmalware (ai score=85)
VBA32Trojan.Sabsik.TE
MalwarebytesMalware.AI.4170113603
PandaGeneric Suspicious
TencentWin32.Virus.Expiro.Eeht
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDO!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.000e0c
AvastWin32:Evo-gen [Susp]

How to remove TrojanDownloader:Win32/SmallAgent.AW!MTB?

TrojanDownloader:Win32/SmallAgent.AW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment