Spy Trojan

TrojanSpy:MSIL/SmallAgent.SBR!MSR removal

Malware Removal

The TrojanSpy:MSIL/SmallAgent.SBR!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/SmallAgent.SBR!MSR virus can do?

  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine TrojanSpy:MSIL/SmallAgent.SBR!MSR?


File Info:

name: A9AC99AFD1CD00D89AA3.mlw
path: /opt/CAPEv2/storage/binaries/5a9ecc1c67487300d3cd43cd9ef0b51a3b00511b9fd0880c8133c4e845b94390
crc32: 72053F6C
md5: a9ac99afd1cd00d89aa34e8ba456fee5
sha1: daa75807bebafc3c6776d93ca65d4853dc2de159
sha256: 5a9ecc1c67487300d3cd43cd9ef0b51a3b00511b9fd0880c8133c4e845b94390
sha512: 7d810e0e680a427a37d1d0a073dccbb2162a79adcc73242e74ace9bd07f11592b55dec96571ec0aed094b74994c3ec05a91fd50da4690eece52333262985d538
ssdeep: 192:upMs6zHNQ/SuJeMZZ3f93VnjdwXzq3T2DZA:ZH6JeMJFnhwXOC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19512F819ABC8E671CDB70A30ECB367504B70E75040A3DA9F6AC985172DE7F090A923F0
sha3_384: 20cdf7b57c630c0877121aa9f7f2bdbc80b4db1d8f4d938317ac82579a9354047b110bdb3f88d1055f0ba13c0c85184e
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-02-21 01:37:44

Version Info:

Translation: 0x0000 0x04b0
Comments: PvGFqaeXmqBfpj
CompanyName: XkJLlFhnwZJlRNTei
FileDescription: xyeQMNtLkZyfn
FileVersion: 1.0.0.0
InternalName: Moodily.exe
LegalCopyright: LcpXQsHeRnIFvuLmZla
LegalTrademarks: xEKbvgCUXRkHdINob
OriginalFilename: Moodily.exe
ProductName: iAYKHddViAwp
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

TrojanSpy:MSIL/SmallAgent.SBR!MSR also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Agent.4!c
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Generic.zt
McAfeeGenericRXNK-BV!A9AC99AFD1CD
Cylanceunsafe
ZillyaTrojan.Agent.Win32.1789383
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00576c111 )
AlibabaTrojan:Win32/SmallAgent.3b3
K7GWTrojan ( 00576c111 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.TZL
APEXMalicious
ClamAVWin.Malware.Msilkrypt-9839010-0
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.GenericKDZ.73325
SUPERAntiSpywareBackdoor.BlackSpider/Variant
MicroWorld-eScanTrojan.GenericKDZ.73325
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Agent.yhq
EmsisoftTrojan.GenericKDZ.73325 (B)
F-SecureHeuristic.HEUR/AGEN.1308474
DrWebTrojan.DownLoader36.36404
VIPRETrojan.GenericKDZ.73325
TrendMicroTrojan.MSIL.USICE.SMJCDP2
SophosTroj/MSIL-PNC
IkarusTrojan-Downloader.MSIL.Agent
GoogleDetected
AviraHEUR/AGEN.1308474
Antiy-AVLTrojan/MSIL.Agent.tzl
MicrosoftTrojanSpy:MSIL/SmallAgent.SBR!MSR
ArcabitTrojan.Generic.D11E6D
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataMSIL.Trojan.Agent.AXW
VaristW32/MSIL_Troj.AHV.gen!Eldorado
AhnLab-V3Malware/Win32.RL_Generic.C4307049
BitDefenderThetaGen:NN.ZemsilF.36680.am0@aiiNOy
VBA32Trojan.MSIL.Krypt
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingTrojan.Agent!1.D274 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/SmallAgent.A!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove TrojanSpy:MSIL/SmallAgent.SBR!MSR?

TrojanSpy:MSIL/SmallAgent.SBR!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Spy Trojan

What is “TrojanSpy:MSIL/SmallAgent.SBR!MSR”?

Malware Removal

The TrojanSpy:MSIL/SmallAgent.SBR!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/SmallAgent.SBR!MSR virus can do?

  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine TrojanSpy:MSIL/SmallAgent.SBR!MSR?


File Info:

name: 99A71B03D718A33C09E9.mlw
path: /opt/CAPEv2/storage/binaries/83a5796b4ae302fbd9a92a2cb9a2c0731bc352ccc0793a0462b6291a54dd83c3
crc32: B6FEC439
md5: 99a71b03d718a33c09e99b65b9f738a3
sha1: 75e61a2b55073ae0d715661ea49fd4f07cdd3acb
sha256: 83a5796b4ae302fbd9a92a2cb9a2c0731bc352ccc0793a0462b6291a54dd83c3
sha512: e9efb8fa072aa6eb405d1214942deaf3dfb5a5fb7b8f0f5504118c7583fc2fe6a2aeec0365db0d1ee1cd8815ad8dd2969f98a55166fdcc907c862929fa8018ca
ssdeep: 192:tMsiEXVwV9IWeMZZ3j93Vnjdwvza3LJy6KjL:RVwbIWeM9FnhwvWtdKj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172122B59E788E679EDB71770ECB3530083B0DB504463DA5F6A98890B39E3B5846A36F0
sha3_384: d1c3db5998e24ccc2bb6761b7948e2ab6e439567e6ba433caa5ba723341d64ba5b3353491a40380748c47909e23597f0
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-02-11 01:38:57

Version Info:

Translation: 0x0000 0x04b0
Comments: tiiflCLmaSgVRRhmTQn
CompanyName: TMincFalKdYaG
FileDescription: WAJvaOLsQcDJltnIbqo
FileVersion: 1.0.0.0
InternalName: Twisters.exe
LegalCopyright: DHZrmbLtGaLQAIAtIsj
LegalTrademarks: LNYbSQnWcyrotGGkxx
OriginalFilename: Twisters.exe
ProductName: ZMthCYRLdNkr
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

TrojanSpy:MSIL/SmallAgent.SBR!MSR also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Agent.4!c
DrWebTrojan.DownLoader36.36404
MicroWorld-eScanTrojan.GenericKDZ.73333
SkyhighBehavesLike.Win32.Generic.zt
McAfeeGenericRXNK-BV!99A71B03D718
Cylanceunsafe
ZillyaTrojan.AgentGen.Win32.82
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00576c111 )
AlibabaTrojan:Win32/SmallAgent.3b3
K7GWTrojan ( 00576c111 )
BitDefenderThetaGen:NN.ZemsilF.36680.am0@aWiq8Mm
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.TZL
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Msilkrypt-9839010-0
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.GenericKDZ.73333
SUPERAntiSpywareBackdoor.BlackSpider/Variant
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Agent.yhq
EmsisoftTrojan.GenericKDZ.73333 (B)
F-SecureHeuristic.HEUR/AGEN.1306570
VIPRETrojan.GenericKDZ.73333
TrendMicroTrojan.MSIL.USICE.SMJCDP2
SophosTroj/MSIL-PNC
IkarusTrojan-Downloader.MSIL.Agent
JiangminTrojan.MSIL.utwm
VaristW32/MSIL_Troj.AHV.gen!Eldorado
AviraHEUR/AGEN.1306570
Antiy-AVLTrojan/MSIL.Agent.tzl
Kingsoftmalware.kb.c.694
MicrosoftTrojanSpy:MSIL/SmallAgent.SBR!MSR
ArcabitTrojan.Generic.D11E75
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataMSIL.Trojan.Agent.AXW
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R363865
VBA32Trojan.MSIL.Krypt
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingTrojan.Agent!1.D274 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/SmallAgent.A!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanSpy:MSIL/SmallAgent.SBR!MSR?

TrojanSpy:MSIL/SmallAgent.SBR!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment