Trojan

What is “Trojan:Win32/Smokeloader.GXZ!MTB”?

Malware Removal

The Trojan:Win32/Smokeloader.GXZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Smokeloader.GXZ!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan:Win32/Smokeloader.GXZ!MTB?


File Info:

name: 3054B8493E2F4399F7D9.mlw
path: /opt/CAPEv2/storage/binaries/e81c8acd2422463483d94d82997f5bea8327979db2ff876b4d71a2992b8553d8
crc32: 1A3A8408
md5: 3054b8493e2f4399f7d973d7be85d63d
sha1: c8098f1dda38115cbf19a4b37c9908256edf24b5
sha256: e81c8acd2422463483d94d82997f5bea8327979db2ff876b4d71a2992b8553d8
sha512: e7d827b3e30ee03043c7f5a6060b69e359677e3bd11539accc9e0d2f357485980644a3b5356e2b43c4381ce8f642490cd3ef43ef8909dbc6efb6d783b8945bbf
ssdeep: 3072:lnAwYhs5AxMPMnbS38P5UkAVKWYYM7tXfJpiuf:iRs59PMnbSXJKag
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19CF3AD217391C832D0D6163484BACBBD1A7BBC622A714287AB943B6F3FB12D0593D757
sha3_384: 1e0d9f0887f418f678cc3f3e4baca7b1f6a756fa584bf6457bf3da1cd2481a4f3d378cf27136f87c761b202a34c7e412
ep_bytes: e84b2f0000e989feffff8bff558bec81
timestamp: 2023-09-01 03:58:04

Version Info:

FileVersion: 12.3.3.493
ProductVersion: 2.16.10.51
InternalName: Slupido
CompanyName: Torchok
Translation: 0x149d 0x0235

Trojan:Win32/Smokeloader.GXZ!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.71791109
FireEyeGeneric.mg.3054b8493e2f4399
SkyhighBehavesLike.Win32.Dropper.ch
McAfeeArtemis!3054B8493E2F
MalwarebytesTrojan.MalPack.GS
SangforRansom.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HWLA
APEXMalicious
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.71791109
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
EmsisoftTrojan.GenericKD.71791109 (B)
VIPRETrojan.GenericKD.71791109
TrendMicroTrojan.Win32.SMOKELOADER.YXEB2Z
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ADH
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
GDataWin32.Trojan-Downloader.SmokeLoader.R9RZ6K
GoogleDetected
AviraTR/Crypt.Agent.itmvu
VaristW32/Kryptik.LSE.gen!Eldorado
Kingsoftmalware.kb.a.999
ArcabitTrojan.Generic.D4477205
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Smokeloader.GXZ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.AGEN.R637010
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.kq0@aqWvqxhi
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXEB2Z
RisingTrojan.Generic@AI.100 (RDML:U/waCG2Y23P9vn+Nk9BurQ)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.771626.susgen
FortinetW32/PossibleThreat
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.dda381
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Smokeloader.GXZ!MTB?

Trojan:Win32/Smokeloader.GXZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment