Malware

BrowserModifier:Win32/Smudplu information

Malware Removal

The BrowserModifier:Win32/Smudplu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BrowserModifier:Win32/Smudplu virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Loads a driver
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
d1y2jryd6u59ns.cloudfront.net
d23ocewf5ttxmu.cloudfront.net

How to determine BrowserModifier:Win32/Smudplu?


File Info:

crc32: 0B9B32D6
md5: 0474e734e8a510ccd158b736191a0ae3
name: smwdna.exe
sha1: 0ca09cddbf3c211847ce41ba67400e12030a8893
sha256: 1e1a200d626b023216a54bd65c237635ca615a4afb114f7d67fee48e3a4140af
sha512: 90eabd40b06812d70732dcd5ab148813cdf3459292cb013ae319654deb52878b14bf36a4b61658c132c5a9fa07e3b786b7f562a40cdbf2bf1e738b92b8f7669b
ssdeep: 49152:Hc6QFR8GiWbIHnyDfSSj+QXOdASeMKI9ttfDVNaGAvfeYNuIuiL4pVe4H:HcPYTHnwfrjDeR9TmF3uIuiL4pV5
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

FileVersion: 2.3.15.1906
OriginalFilename: smw.exe
ProductVersion: 2.3.15.1906
Translation: 0x0409 0x04e4

BrowserModifier:Win32/Smudplu also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Generic.15519705
FireEyeGeneric.mg.0474e734e8a510cc
McAfeeArtemis!0474E734E8A5
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabAdware.Win64.Shopper.mDEl
K7AntiVirusTrojan ( 0052ecd81 )
BitDefenderTrojan.Generic.15519705
K7GWTrojan ( 0052ecd81 )
Cybereasonmalicious.4e8a51
TrendMicroPUA_SPEEDBIT.SM
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataWin64.Application.SpeedBit.B
Kasperskynot-a-virus:HEUR:AdWare.Win32.WatchMan.gen
AlibabaRiskWare:Win32/SSPro.c05d0097
NANO-AntivirusTrojan.Win64.SpeedBit.ehusth
ViRobotAdware.Speedbit.3082028
TencentWin32.Trojan.Sbwatchman.Eem
SophosGeneric PUA II (PUA)
ComodoMalware@#2b0376zsadcge
F-SecurePotentialRisk.PUA/SearchModule.Gen
DrWebAdware.Privitize.147
ZillyaAdware.WatchMan.Win32.274
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftApplication.AdSpeed (A)
IkarusPUA.SBWatchman
WebrootW32.Adware.Gen
AviraPUA/SearchModule.Gen
Antiy-AVLTrojan/Win32.BTSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D2A264
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.WatchMan.gen
MicrosoftBrowserModifier:Win32/Smudplu
CynetMalicious (score: 90)
AhnLab-V3Adware/Win32.Shopper.C839131
MAXmalware (ai score=100)
VBA32AdWare.Win64.Shopper
MalwarebytesPUP.Optional.Goobzo
ZonerTrojan.Win32.49045
ESET-NOD32Win32/Agent.AB potentially unwanted
TrendMicro-HouseCallPUA_SPEEDBIT.SM
RisingMalware.Vigram!8.F6AF (TFE:5:duh5Av8IcyU)
YandexRiskware.Agent!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/SBWatchman
BitDefenderThetaGen:NN.ZexaF.34136.vuW@ame1MLii
AVGNSIS:Adware-VS [PUP]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM42.1.Malware.Gen

How to remove BrowserModifier:Win32/Smudplu?

BrowserModifier:Win32/Smudplu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment