Spy Trojan

TrojanSpy:MSIL/SmallAgent.SBR!MSR (file analysis)

Malware Removal

The TrojanSpy:MSIL/SmallAgent.SBR!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/SmallAgent.SBR!MSR virus can do?

  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine TrojanSpy:MSIL/SmallAgent.SBR!MSR?


File Info:

name: FF740C4512C9A5E7EE50.mlw
path: /opt/CAPEv2/storage/binaries/ab1058fc405dd69a61f6a5ab5658b5f7f005204bb31dbd1283887c569b4b9d88
crc32: 32D8C973
md5: ff740c4512c9a5e7ee502879e29fb81f
sha1: bfab5a7d7694e98304ab7808cb25a976bf57af0c
sha256: ab1058fc405dd69a61f6a5ab5658b5f7f005204bb31dbd1283887c569b4b9d88
sha512: 94813727c57bdcb73df79496bd9ebb972ce59acfba7caec424f58d857abe3e876ed4f65417f7f52099f294cc357eb3ad40617a5ef3ffe69e6a8f2eea4cdecb7d
ssdeep: 192:+MsaDUSOV2o3reMZZ3893VnjdwvzJ3CZWX:zoreM4FnhwvtyZW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B121955F784E231DDBB0B31ECB353404E70A7404467CA9F6BC9891B6DE3B585A622F0
sha3_384: 59f3392c1f8b87074ed85060a2ef4658558bf4466c6c9d54d99cd2bb2f7f272755df54c14d1689a768595ee2c065d86f
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-02-03 08:42:09

Version Info:

Translation: 0x0000 0x04b0
Comments: XBwnIXPgOwyJfPernc
CompanyName: YUSQhEGejSOfBjHujXe
FileDescription: ElFjsoudPbyOpZAvxr
FileVersion: 1.0.0.0
InternalName: Heps.exe
LegalCopyright: riKadMIQSIvUbNMpbnT
LegalTrademarks: sAWuIHDyOBJHZqhZ
OriginalFilename: Heps.exe
ProductName: wAeAZPRJwfSAdqbc
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

TrojanSpy:MSIL/SmallAgent.SBR!MSR also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader36.36404
MicroWorld-eScanGen:Trojan.Mardom.PN.16
SkyhighBehavesLike.Win32.Generic.zt
McAfeeArtemis!FF740C4512C9
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Trojan.Mardom.PN.16
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00576c111 )
AlibabaTrojan:Win32/SmallAgent.3b3
K7GWTrojan ( 00576c111 )
BitDefenderThetaGen:NN.ZemsilF.36680.am0@aaksNNm
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.TZL
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Msilkrypt-9839010-0
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Trojan.Mardom.PN.16
SUPERAntiSpywareTrojan.Agent/Gen-Faker[desc]
AvastWin32:MalwareX-gen [Trj]
RisingTrojan.Agent!1.D274 (CLASSIC)
EmsisoftGen:Trojan.Mardom.PN.16 (B)
F-SecureHeuristic.HEUR/AGEN.1308954
ZillyaTrojan.AgentGen.Win32.82
TrendMicroTrojan.MSIL.USICE.SMJCDP2
SophosTroj/MSIL-PNC
IkarusTrojan-Downloader.MSIL.Agent
VaristW32/MSIL_Troj.AHV.gen!Eldorado
AviraHEUR/AGEN.1308954
Antiy-AVLTrojan/MSIL.Agent.tzl
MicrosoftTrojanSpy:MSIL/SmallAgent.SBR!MSR
ArcabitTrojan.Mardom.PN.16
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataMSIL.Trojan.Agent.AXW
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R363865
VBA32Trojan.MSIL.Krypt
Cylanceunsafe
PandaTrj/GdSda.A
TencentTrojan.Win32.Agent.yhq
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/SmallAgent.A!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanSpy:MSIL/SmallAgent.SBR!MSR?

TrojanSpy:MSIL/SmallAgent.SBR!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment