Adware

How to remove “Adware.SMSHoax.25 (B)”?

Malware Removal

The Adware.SMSHoax.25 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.SMSHoax.25 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Adware.SMSHoax.25 (B)?


File Info:

name: 4A5B75071728256FEE8B.mlw
path: /opt/CAPEv2/storage/binaries/602b69396f1f8ef94595878018f210504e9890835a7d39290ac78523477c8150
crc32: 09A81AD9
md5: 4a5b75071728256fee8b3dd6d7ec8309
sha1: ebe0c2f6ee95b52f863ea711da9ea1677cad2a88
sha256: 602b69396f1f8ef94595878018f210504e9890835a7d39290ac78523477c8150
sha512: ded0f8a0a06cf01f22bfc2a78c63b8609ed1605d880a39ac0dc34b30daeb5f3e9930c41e0928c25c4f476723d9456811e58d8135bd38edee44a45d155405c6f3
ssdeep: 196608:koGoDFr9mgRQortxUlX84nrfkCbwLiP9ZT2qB/8zqycBGdgM+6hck:koTDFr9mLmwG49wiZzB/CqDagc9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DF8633010654FA9CF6570E7AE946C3F2C28D5C47F628809361A47FB7F5B78D4A0AF198
sha3_384: 072d7f5f678b975dada20d6c9abfa7641f49bb6cb83b87f053bc43cb0109ae0defe158fd400a0b4e3e7c917009405ee2
ep_bytes: 60be0040d1008dbe00d06effc787ec70
timestamp: 2008-12-02 15:41:29

Version Info:

0: [No Data]

Adware.SMSHoax.25 (B) also known as:

LionicHacktool.Win32.ArchSMS.lmoi
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.SMSHoax.25
FireEyeGeneric.mg.4a5b75071728256f
CAT-QuickHealHoax.Archsms.21852
McAfeeGenericRXAA-AA!4A5B75071728
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforTrojan.Win32.Kryptik.MHU
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaVirTool:Win32/Obfuscator.31180734
VirITTrojan.Win32.SMSSend.SF
CyrenW32/Kryptik.DKT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.MHU
APEXMalicious
ClamAVWin.Trojan.Agent-1017783
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Adware.SMSHoax.25
NANO-AntivirusRiskware.Win32.ArchSMS.utmvj
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b4b1f8
Ad-AwareGen:Variant.Adware.SMSHoax.25
SophosMal/Generic-R + Mal/EncPk-ZC
ComodoMalware@#ur15m08o3461
DrWebTrojan.SMSSend.473
ZillyaTrojan.ArchSMS.Win32.377
TrendMicroTROJ_GEN.USCMF16
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
EmsisoftGen:Variant.Adware.SMSHoax.25 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Adware.SMSHoax.25
JiangminHoax.ArchSMS.bcm
WebrootW32.Adware.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.323628A
KingsoftWin32.Troj.Diple.fo.(kcloud)
ArcabitTrojan.Adware.SMSHoax.25
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 99)
BitDefenderThetaAI:Packer.BA9DBEF320
ALYacGen:Variant.Adware.SMSHoax.25
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallTROJ_DIPLE.CFR
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!K9QWYfIJ3gg
Ikarusnot-a-virus:Hacktool.SMSHoax
eGambitUnsafe.AI_Score_93%
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.2015605.susgen

How to remove Adware.SMSHoax.25 (B)?

Adware.SMSHoax.25 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment