Trojan

TrojanDownloader:VBS/Sminager.I removal guide

Malware Removal

The TrojanDownloader:VBS/Sminager.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:VBS/Sminager.I virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Harvests cookies for information gathering

How to determine TrojanDownloader:VBS/Sminager.I?


File Info:

name: 08C367DCCC49197DDCC9.mlw
path: /opt/CAPEv2/storage/binaries/ec3e601df45cffb358766ec849abda6562ac67323366e906779196d19e1344e6
crc32: 1E397B50
md5: 08c367dccc49197ddcc95be5d1c5b794
sha1: a49910117d884e753a4d5cf88a59be1b8fc8e15c
sha256: ec3e601df45cffb358766ec849abda6562ac67323366e906779196d19e1344e6
sha512: 4b39d6b29dfe9259d1dc5f8f34a0d84f5f008488ea8a7e1f8548b6e13599db59c274f68674ac18708a0fe8e8481eaf4c618666ee58fe2bd5a78f9579257d2783
ssdeep: 3072:u86dHxGNd5E9o7lOCET1NNAhTtaWmZzFfokt+F9EepWL2tIX83UYobykj/GwKYEt:ulJ4Nwo7lOpT2hkWGzxU7p05YobNBEt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E64E4116683E0FDD7EA5530C9F6E3605D29FB2C2A357DDA73B4B7280A30C81552EE62
sha3_384: 7041c23d2de7ff9a0527556b0adee7d06b3716c380909de69d181d81f302910933b9cc74bdd24f9559597ec8707d7708
ep_bytes: e8f7040000e98efeffff3b0da8d04200
timestamp: 2017-05-23 11:58:52

Version Info:

0: [No Data]

TrojanDownloader:VBS/Sminager.I also known as:

LionicTrojan.Win32.Snojan.4!c
MicroWorld-eScanTrojan.GenericKD.6161360
FireEyeGeneric.mg.08c367dccc49197d
ALYacTrojan.GenericKD.6161360
MalwarebytesMalware.AI.955714360
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Snojan.bucl
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:VBS/Snojan.83c42423
K7GWTrojan-Downloader ( 0051afe31 )
Cybereasonmalicious.ccc491
BaiduVBS.Trojan-Downloader.Agent.ug
CyrenJS/Downldr.QG.V!Eldorado
SymantecTrojan.VBdrop
ESET-NOD32VBS/TrojanDownloader.Small.NGM
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Snojan-6611652-0
KasperskyTrojan.Win32.Snojan.bucl
BitDefenderTrojan.GenericKD.6161360
NANO-AntivirusTrojan.Win32.Snojan.eutkxw
AvastVBS:Downloader-ASQ [Trj]
TencentWin32.Trojan.Snojan.Hpb
EmsisoftTrojan.GenericKD.6161360 (B)
ComodoMalware@#v5jgrsixxrqe
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.fh
SophosTroj/VBSDldr-U
IkarusTrojan-Downloader.VBS.Small
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASSuf.229F7
MicrosoftTrojanDownloader:VBS/Sminager.I
GDataTrojan.GenericKD.6161360
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Snojan.C2245066
McAfeeRDN/Generic Downloader.x
VBA32Trojan.Script
CylanceUnsafe
RisingDownloader.CoinMiner!8.131A (TOPIS:E0:nbpD5eUrOWH)
YandexTrojan.DL.Alien!TTR0EF1Dzqk
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetVBS/Small.NGR!tr.dldr
AVGVBS:Downloader-ASQ [Trj]
PandaTrj/CI.A

How to remove TrojanDownloader:VBS/Sminager.I?

TrojanDownloader:VBS/Sminager.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment