Adware

How to remove “Adware.SMSHoax.25”?

Malware Removal

The Adware.SMSHoax.25 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.SMSHoax.25 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Adware.SMSHoax.25?


File Info:

name: 2E2053C5E3A86A842E1D.mlw
path: /opt/CAPEv2/storage/binaries/3f631824e9d0b1332c4d791065b740c7edefabe11878b744dd35fff53ba67438
crc32: 1DF25C5F
md5: 2e2053c5e3a86a842e1df4101c8322dd
sha1: c1f29ea66d689f50a5f3d0d73658f1bbb28e3222
sha256: 3f631824e9d0b1332c4d791065b740c7edefabe11878b744dd35fff53ba67438
sha512: 0aa1d3f2db1cac9140f9392285d04d42e84ef8da2035529526a4c491d237f6a010a27d74ab315ae9dd96e0d37a1acfc2fd44cf682c1dd2b8445329a21f4bcdf4
ssdeep: 196608:koGoDFr9U/6/LD8I4rwz9bJMQ6br+6bikW7/H4d4eeNIcUzHy6:koTDFr9g6X1aEb6bS7/HheLHy6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15CB6330E2B0FC96FF6649571C737A5F0E4D07E1ADE044297E2263DD6B93E6800C6B4A9
sha3_384: b5a473e885e350423363655911c2c2c5eb88dc448dabfa3bd7e412241e3e6d13dbc236aeb78e8dd6c96291c887e0bfe5
ep_bytes: 60be0040d1008dbe00d06effc787ec70
timestamp: 2008-12-02 15:41:29

Version Info:

0: [No Data]

Adware.SMSHoax.25 also known as:

LionicHacktool.Win32.ArchSMS.3!c
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.473
MicroWorld-eScanGen:Variant.Adware.SMSHoax.25
FireEyeGeneric.mg.2e2053c5e3a86a84
ALYacGen:Variant.Adware.SMSHoax.25
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforTrojan.Win32.ULPM.Gen
AlibabaVirTool:Win32/Obfuscator.95b32ace
Cybereasonmalicious.5e3a86
BitDefenderThetaAI:Packer.BA9DBEF320
VirITTrojan.Win32.SMSSend.SF
CyrenW32/Kryptik.DKT.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.MHU
ClamAVWin.Trojan.Agent-1017783
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Adware.SMSHoax.25
NANO-AntivirusRiskware.Win32.ArchSMS.utmvj
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b4b1f8
Ad-AwareGen:Variant.Adware.SMSHoax.25
SophosMal/Generic-S + Mal/EncPk-ZC
ComodoMalware@#1mdkfu3dvcufl
ZillyaTrojan.ArchSMS.Win32.377
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Adware.SMSHoax.25 (B)
Ikarusnot-a-virus:Hacktool.SMSHoax
GDataGen:Variant.Adware.SMSHoax.25
JiangminHoax.ArchSMS.bcm
WebrootW32.Adware.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.323628A
ArcabitTrojan.Adware.SMSHoax.25
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ditertag.A
CynetMalicious (score: 99)
McAfeeGenericRXAA-AA!2E2053C5E3A8
VBA32Trojan.Zeus.EA.0999
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!K9QWYfIJ3gg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Adware.SMSHoax.25?

Adware.SMSHoax.25 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment