Spy Trojan

TrojanSpy:MSIL/SmallAgent.SBR!MSR removal guide

Malware Removal

The TrojanSpy:MSIL/SmallAgent.SBR!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/SmallAgent.SBR!MSR virus can do?

  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine TrojanSpy:MSIL/SmallAgent.SBR!MSR?


File Info:

name: 3AA0FCFC4EFE120C4CAC.mlw
path: /opt/CAPEv2/storage/binaries/2d307dcaabd2731f90e7192227ce62cba24fb05436f6344b8a8f6fc32419d233
crc32: D0C9233D
md5: 3aa0fcfc4efe120c4caca7b409617bdb
sha1: 12ab1ab3ff620cc92f49c45ee2f7f2b1ca5d9574
sha256: 2d307dcaabd2731f90e7192227ce62cba24fb05436f6344b8a8f6fc32419d233
sha512: f7046a2867b3a50b3bd560da9cefef03796cd56679401283b75390703b7dbb85de4a27c82a3822ece7b76fe9779c584fe2b45321b2997bb4b50370c3edbc2021
ssdeep: 192:C+y4GN3qO+UqeMZZ3w93VnjdwvuVb3s5G:4ZqTeM0FnhwvMc5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A012F728E7C8D372DDAB0B31E9B353404E70DB4044A7DA5F66D9851B2DE7B281A672B0
sha3_384: 3ae74f21746399dfc4b5a6fc27e065cca0b51c32bc87b2671d4c370320311fabd72f3f0cd7bb671330b8ae430a9e0769
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-01-29 17:32:27

Version Info:

Translation: 0x0000 0x04b0
Comments: MAuBhkcxaNlUia
CompanyName: QQFGHAqgCycuUJUDM
FileDescription: aNhFZiTkOnAmxHaWJV
FileVersion: 1.0.0.0
InternalName: Embody.exe
LegalCopyright: XGUyhOxhvpNTdCm
LegalTrademarks: hHaWqPSGjoZonqDR
OriginalFilename: Embody.exe
ProductName: IJYAmyfQBMMLlqprF
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

TrojanSpy:MSIL/SmallAgent.SBR!MSR also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Mardom.PN.17
SkyhighBehavesLike.Win32.Generic.zm
McAfeeGenericRXMU-QB!3AA0FCFC4EFE
Cylanceunsafe
ZillyaTrojan.Agent.Win32.1771871
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:MSIL/SmallAgent.0e93211a
K7GWTrojan ( 00576c111 )
K7AntiVirusTrojan ( 00576c111 )
BitDefenderThetaGen:NN.ZemsilF.36680.am0@aebja!e
VirITTrojan.Win32.Dnldr36.CBXE
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.TZL
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Msilkrypt-9839010-0
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Trojan.Mardom.PN.17
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Generic.zc
EmsisoftGen:Trojan.Mardom.PN.17 (B)
F-SecureHeuristic.HEUR/AGEN.1308474
DrWebTrojan.DownLoader36.36430
VIPREGen:Trojan.Mardom.PN.17
TrendMicroTrojan.MSIL.USICE.SMJCDP2
SophosTroj/MSIL-PNC
IkarusTrojan-Downloader.MSIL.Agent
VaristW32/MSIL_Troj.AHV.gen!Eldorado
AviraHEUR/AGEN.1308474
Antiy-AVLGrayWare/MSIL.Smallagent.a
Kingsoftmalware.kb.c.686
MicrosoftTrojanSpy:MSIL/SmallAgent.SBR!MSR
ArcabitTrojan.Mardom.PN.17
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataMSIL.Trojan.Agent.AXW
GoogleDetected
AhnLab-V3Malware/Win.Generic.R374107
VBA32Trojan.MSIL.Krypt
TACHYONTrojan/W32.DN-Agent.9728.AW
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingTrojan.Agent!1.D274 (CLASSIC)
YandexTrojan.Agent!RAuWU7IMPXE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/SmallAgent.A!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove TrojanSpy:MSIL/SmallAgent.SBR!MSR?

TrojanSpy:MSIL/SmallAgent.SBR!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment