Virus

Virus:Win32/Smee.A removal instruction

Malware Removal

The Virus:Win32/Smee.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Smee.A virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Smee.A?


File Info:

name: 739D3B62824A9F22BCF5.mlw
path: /opt/CAPEv2/storage/binaries/a647c6a4b549bc22d6858924db9b07c503104ff97645fe0e8d8a1280367034fe
crc32: 7D964658
md5: 739d3b62824a9f22bcf528354b4f9ba0
sha1: e76aa2fe09b4330aac6304ea4c5a86951be4defa
sha256: a647c6a4b549bc22d6858924db9b07c503104ff97645fe0e8d8a1280367034fe
sha512: 9becb12d35e27465f3b4f9aaf435f07379f22253a45002703fc6b729d399391098231ab1dd7c76f0da5990f258b6eeb953921878e89a61c68472f25f71ef3c84
ssdeep: 12288:hRvd6Ps7Wo1s7Z8FxgV1R16aexCUJg/5MKmpTVptf3lP71moemc:hVd6UCoo9V1R1vQ+mKmpntfF71I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190058D357AE48035E4B252B4566D6276117ABCB00F3A40CFB3D407EEA970BD1AA35B73
sha3_384: 458bb96368ce0113342c27deed6c69214b39fef33fb3e96d5df086b861110f49a6fbda4ffd1ef94fcfb6b3dfe1ba5547
ep_bytes: 60e802000000c3905883e80683e80450
timestamp: 2014-09-03 07:14:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: External Installer
FileVersion: 10.0.50903.0 built by: VSTO_Rel
InternalName: Install.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Install.exe
ProductName: Microsoft® Visual Studio® 2010
ProductVersion: 10.0.50903.0
Translation: 0x0409 0x04b0

Virus:Win32/Smee.A also known as:

BkavW32.RomanticPtv.PE
LionicVirus.Win32.Agent.n!c
DrWebWin32.Cave
MicroWorld-eScanWin32.Sagev.A
ClamAVWin.Malware.Sagev-6725475-0
FireEyeGeneric.mg.739d3b62824a9f22
CAT-QuickHealW32.Agent.CB
McAfeeW32/Caveduck.a
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.Agent.Win32.11
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00094cc11 )
AlibabaVirus:Win32/Agent.e967db1d
K7GWVirus ( 00094cc11 )
Cybereasonmalicious.e09b43
BitDefenderThetaAI:FileInfector.F00B2D890D
VirITWin32.Bonka.A
CyrenW32/Fidameg.A
SymantecW32.Loorp.B!inf
Elasticmalicious (high confidence)
ESET-NOD32Win32/Delf.NAP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Agent.cb
BitDefenderWin32.Sagev.A
NANO-AntivirusVirus.Win32.Agent.ruvk
AvastWin32:Agent-AIXK
RisingWin32.Agent.da (CLASSIC)
EmsisoftWin32.Sagev.A (B)
F-SecureMalware.W32/Vetor.I
BaiduWin32.Virus.Agent.b
VIPREWin32.Sagev.A
TrendMicroPE_FIDAMEG.A
McAfee-GW-EditionBehavesLike.Win32.Virut.cm
SophosW32/Vetor-I
SentinelOneStatic AI – Malicious PE
GDataWin32.Sagev.A
JiangminWin32/Agent.f
AviraW32/Vetor.I
MAXmalware (ai score=100)
Antiy-AVLVirus/Win32.Agent.cb
XcitiumVirus.Win32.Delf.NAP0@1ij8ae
ArcabitWin32.Sagev.A
ZoneAlarmVirus.Win32.Agent.cb
MicrosoftVirus:Win32/Smee.A
GoogleDetected
AhnLab-V3Win32/Sagev
Acronissuspicious
VBA32TrojanRansom.Gen
ALYacWin32.Sagev.A
TACHYONTrojan/W32.Jacard
Cylanceunsafe
PandaW32/Miaketa.A
TrendMicro-HouseCallPE_FIDAMEG.A
TencentVirus.Win32.Bonka.c
IkarusVirus.Win32.Agent
MaxSecureVirus.W32.Agent.CB
FortinetW32/Agent.CB
AVGWin32:Agent-AIXK
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Smee.A?

Virus:Win32/Smee.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment