Trojan

Trojan:Win32/Smokeloader.G!MTB removal

Malware Removal

The Trojan:Win32/Smokeloader.G!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Smokeloader.G!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Smokeloader.G!MTB?


File Info:

name: EEC15B61F030FA9D500E.mlw
path: /opt/CAPEv2/storage/binaries/89f92e992d085c71721d1fc4ba4885f4ad11f4440b13a3094e8265ae0ebab0e8
crc32: 48EE79D4
md5: eec15b61f030fa9d500e54d90e67e8bf
sha1: f22602d6eb4b59c21ed5663f65160650cc2b101b
sha256: 89f92e992d085c71721d1fc4ba4885f4ad11f4440b13a3094e8265ae0ebab0e8
sha512: 57ddac0f977136e3985d6b329b957497ba3bdd5cc794abb3873832ed6ebab54d332de44f5bcd4a3c5764aed0cd84307447534ab2b96018e690c696722abe66d9
ssdeep: 24576:Z7Ht6AsrGgW7r0t/1sbtnSns/9Vi7sAYT/BA:Zp6LW7r0t/iM267sDBA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B035BF6078DA9132EDE310F746ECB932062DE5F0072646DF56B627EEA6147C22F32587
sha3_384: bd2fe5a884f2184ea4982a3eb8a85d88130e802b7ebc7a6dbeed1edf12c62ac47528e269faf5b488690b835b1d51da05
ep_bytes: e9f2740400e944dc0500e9e3f90400e9
timestamp: 2022-08-28 11:46:15

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Device driver software installation
FileVersion: 5.2.3668.0
InternalName: NDAdmin.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: NDAdmin.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.2.3668.0
Translation: 0x0409 0x04b0

Trojan:Win32/Smokeloader.G!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mokes.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.28157
MicroWorld-eScanGen:Variant.Zusy.436312
FireEyeGen:Variant.Zusy.436312
SkyhighPacked-GEP!EEC15B61F030
ALYacGen:Variant.Zusy.436312
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3883923
SangforBackdoor.Win32.Agent.Vxkq
K7AntiVirusTrojan ( 00597f2a1 )
AlibabaBackdoor:Win32/Smokeloader.bb2f22a8
K7GWTrojan ( 00597f2a1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HQPE
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Keylogger.Lazy-10018607-0
KasperskyHEUR:Backdoor.Win32.Mokes.gen
BitDefenderGen:Variant.Zusy.436312
NANO-AntivirusTrojan.Win32.Mokes.jrwoaa
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.115dd71e
EmsisoftGen:Variant.Zusy.436312 (B)
F-SecureHeuristic.HEUR/AGEN.1303826
VIPREGen:Variant.Zusy.436312
SophosTroj/Steal-CXU
IkarusTrojan.Win32.Redline
GDataGen:Variant.Zusy.436312
JiangminBackdoor.Mokes.ggs
VaristW32/Kryptik.HKL.gen!Eldorado
AviraHEUR/AGEN.1303826
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Zusy.D6A858
ZoneAlarmHEUR:Backdoor.Win32.Mokes.gen
MicrosoftTrojan:Win32/Smokeloader.G!MTB
GoogleDetected
AhnLab-V3Trojan/Win.CrypterX-gen.R512779
Acronissuspicious
McAfeePacked-GEP!EEC15B61F030
MAXmalware (ai score=89)
VBA32Malware-Cryptor.Limpopo
MalwarebytesMalware.AI.4172308009
PandaTrj/Genetic.gen
RisingBackdoor.Mokes!8.619 (TFE:5:S0nMDSQTT0C)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.10612570.susgen
FortinetW32/DotNetPacker.A!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Smokeloader.G!MTB?

Trojan:Win32/Smokeloader.G!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment