Trojan

Trojan:Win32/SmokeLoader.FRX!MTB removal instruction

Malware Removal

The Trojan:Win32/SmokeLoader.FRX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SmokeLoader.FRX!MTB virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/SmokeLoader.FRX!MTB?


File Info:

name: FCAEE42B11C70785CD45.mlw
path: /opt/CAPEv2/storage/binaries/dd60c606a3b15cc13b83f5a2257ab4ab5b18bd8a7bfc02e1149adaec0182c42a
crc32: DB9F04EB
md5: fcaee42b11c70785cd45c6fc6b0ced06
sha1: 42da91a6a3442b692ca6371ce7153cfd72c6eae0
sha256: dd60c606a3b15cc13b83f5a2257ab4ab5b18bd8a7bfc02e1149adaec0182c42a
sha512: 21191e2e511dbaf1ecf2ee1bd01c95bf0627f231519d2ee9a8c14aad0dbbbc346d9ccc24f54bff069404daabaf9f84362ccc8c4338217fca85cfc5ece98200d3
ssdeep: 768:ccb3WnhAQxlxJJM1Ljs3ohN4YrHElLAu4QEkk5rOaOVj1ESuvv:ccyWQxlxk1Ljs8N4uULr4hkadO91s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FD2BF8FDAA1947DD4132179D3961E3E3A07C840B46279A88C263B7F6817F6E48F2943
sha3_384: 7559f17d726f1bdce7adc4493786cb56a86c25e1fd5600a3d4205bcca3fb53289bea2e08a0f0febfdc52469110ad367c
ep_bytes: e800000000750474020b3a83c4048b5c
timestamp: 2022-06-21 14:27:38

Version Info:

0: [No Data]

Trojan:Win32/SmokeLoader.FRX!MTB also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
DrWebTrojan.SmokeLoader.30
MicroWorld-eScanGen:Variant.Ser.Razy.7042
FireEyeGeneric.mg.fcaee42b11c70785
McAfeeRDN/Real Protect-LS
CylanceUnsafe
VIPREGen:Variant.Ser.Razy.7042
SangforTrojan.Win32.SmokeLoader.V5im
K7AntiVirusTrojan ( 00536d121 )
AlibabaTrojan:Win32/SmokeLoader.7af2dd8e
K7GWTrojan ( 00536d121 )
Cybereasonmalicious.b11c70
BitDefenderThetaAI:Packer.DED9EF4A1E
CyrenW32/SmokeLoader.A.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Smokeloader.J
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DIO22
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.7042
NANO-AntivirusTrojan.Win32.Smokeloader.jqoeem
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Imnw
Ad-AwareGen:Variant.Ser.Razy.7042
EmsisoftGen:Variant.Ser.Razy.7042 (B)
TrendMicroTROJ_GEN.R002C0DIO22
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Behav-204
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.hjixn
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.6EA8
MicrosoftTrojan:Win32/SmokeLoader.FRX!MTB
ViRobotTrojan.Win32.Z.Smokeloader.30208.QS
GDataGen:Variant.Ser.Razy.7042
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Smokeldr.C3129113
Acronissuspicious
ALYacGen:Variant.Ser.Razy.7042
TACHYONTrojan/W32.Agent.30208.ACH
MalwarebytesTrojan.MalPack
RisingTrojan.SmokeLoader!8.1008C (TFE:4:wAF724cEbCN)
IkarusTrojan.Win32.SmokeLoader
FortinetW32/Smokeloader.J!tr
AVGWin32:Trojan-gen
PandaTrj/Chgt.AA
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/SmokeLoader.FRX!MTB?

Trojan:Win32/SmokeLoader.FRX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment