Malware

What is “Mal/ArchSMS-A”?

Malware Removal

The Mal/ArchSMS-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/ArchSMS-A virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Mal/ArchSMS-A?


File Info:

name: B9C821F7F50BB0440EAD.mlw
path: /opt/CAPEv2/storage/binaries/5f644d3d06b49c272545998303a3e7c0c73151343d14ec26ccfcadd2ea340b3d
crc32: D9FB89AF
md5: b9c821f7f50bb0440eadb3f18b03e6ef
sha1: 4f41c34aba58d849be0d0dd5a8983976470a37c5
sha256: 5f644d3d06b49c272545998303a3e7c0c73151343d14ec26ccfcadd2ea340b3d
sha512: f89cf6c5d15543516fae8cb79cb69d17448bfd984fa4bf849e0e9cb305854d1546a451bda71b48d72da1647171a9beb50bab1cb086b7f753381a52503201b60f
ssdeep: 49152:jbTGTsoahsc78Xx2jMXJuE1dLBrGuFvZ5K0F4:jGdx2jM5uE1DNlHK7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T153163B15B7E8A62AE7B30F3679B75520113A79966F02C78E12E8A1158C21B50FF7331F
sha3_384: 69b832e82d71a11f49febef500c8f259664bb64b1952511032cbc4d53aee2362d99ea1dda70236b047931d5af6ab3d2e
ep_bytes: 558becb9210000006a006a004975f951
timestamp: 2019-02-27 22:44:11

Version Info:

0: [No Data]

Mal/ArchSMS-A also known as:

FireEyeGeneric.mg.b9c821f7f50bb044
Cybereasonmalicious.aba58d
APEXMalicious
AvastFileRepMalware
SophosMal/ArchSMS-A
McAfee-GW-EditionBehavesLike.Win32.Autorun.rh
GridinsoftRansom.Win32.Wacatac.sa
McAfeeArtemis!B9C821F7F50B
SentinelOneStatic AI – Suspicious PE
BitDefenderThetaAI:Packer.E0F638B21F
AVGFileRepMalware

How to remove Mal/ArchSMS-A?

Mal/ArchSMS-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment