Trojan

TrojanDownloader:Win32/SmallAgent!MTB information

Malware Removal

The TrojanDownloader:Win32/SmallAgent!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/SmallAgent!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Detects Avast Antivirus through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tldrnet.top
loeghaiofiehfihf.to
loirgsiorgididii.to
lefiefijiejdijef.to
linbeafbiaebfiie.to
loueafhuoaefhefu.to
lpleflpokadkeoot.to
laefneabdmemdnaf.to
lezaeazdgzegdget.to
ladbabbabefnefmf.to
lauedaiednaibduf.to
leuaueufuanbbgbg.to
lgauheudbbchaiii.to
lploaeieifuebaub.to
lfubaebeanfienfi.to
lefiaeieiififnnf.to
lbdadnmolaedbfau.to
lnabeuffhshsueur.to
llpaenimonadfueh.to
laedvezdeahfhuea.to
lganieeidiehgihe.to

How to determine TrojanDownloader:Win32/SmallAgent!MTB?


File Info:

crc32: C9CE4950
md5: 8ef8a1ff7c8970d3110aaddf35bf69bc
name: tmprcekicqr
sha1: 8506196713a226987bbf22afa795a5571b518b12
sha256: 9224fb7b92585ab7f05b8849fe29d7b065269b1f901f38dc12946354c3e2ab4c
sha512: 462b13cb203f9f3a075d4018fd70bbc7d3a4dc6e3ef8b15ab7f17a06ebf4019fe86df7679eb29d39109ae8fa2afbbc0d8d2a8063e576ab096489f3219f6da4d9
ssdeep: 3072:MXw0iraSNkpfFo2D5Mj4CfhKvw4uDlrAz/Q99BZqWwBltyd5TrCYU:MXw5aS8oAG4RYjaWik5o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/SmallAgent!MTB also known as:

MicroWorld-eScanGen:Heur.Mint.Zard.39
FireEyeGeneric.mg.8ef8a1ff7c8970d3
CAT-QuickHealTrojanbanker.Cliptoshuffler
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
SangforMalware
K7AntiVirusVirus ( 0055485e1 )
AlibabaTrojanDownloader:Win32/Patched.e730f1c1
K7GWVirus ( 0055485e1 )
Cybereasonmalicious.713a22
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34128.0KW@ausaKjpG
CyrenW32/Agent.BFH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.EQH
TrendMicro-HouseCallTROJ_GEN.R002C0DF420
Paloaltogeneric.ml
GDataGen:Heur.Mint.Zard.39
KasperskyTrojan.Win32.Patched.rw
BitDefenderGen:Heur.Mint.Zard.39
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:BotX-gen [Trj]
RisingWorm.Phorpiex!1.BB1C (CLOUD)
Endgamemalicious (high confidence)
TACHYONWorm/W32.ZeroDownloader
SophosMal/Generic-S
ComodoMalware@#179bsfx386pit
F-SecureMalware.W32/Infector.Gen
DrWebTrojan.DownLoader33.36265
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DF420
McAfee-GW-EditionBehavesLike.Win32.Dropper.cz
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Mint.Zard.39 (B)
APEXMalicious
F-ProtW32/Agent.BFH.gen!Eldorado
JiangminTrojanDownloader.Generic.beop
eGambitUnsafe.AI_Score_71%
AviraW32/Infector.Gen
ArcabitTrojan.Mint.Zard.39
AegisLabTrojan.Win32.Patched.4!c
ZoneAlarmTrojan.Win32.Patched.rw
MicrosoftTrojanDownloader:Win32/SmallAgent!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R282625
Acronissuspicious
VBA32BScope.TrojanBanker.CliptoShuffler
ALYacGen:Heur.Mint.Zard.39
MAXmalware (ai score=89)
Ad-AwareGen:Heur.Mint.Zard.39
MalwarebytesTrojan.Phorpiex
ZonerTrojan.Win32.87633
TencentWin32.Trojan.Patched.Egou
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Agent.EQH!tr
AVGWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.7d0

How to remove TrojanDownloader:Win32/SmallAgent!MTB?

TrojanDownloader:Win32/SmallAgent!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment