Trojan

About “Trojan:Win32/SmokeLoader.IJ!MTB” infection

Malware Removal

The Trojan:Win32/SmokeLoader.IJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SmokeLoader.IJ!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Slovak
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/SmokeLoader.IJ!MTB?


File Info:

name: 57ED22A50E7A067754F9.mlw
path: /opt/CAPEv2/storage/binaries/a8e3bba3c2dfaf065448abde1245c636d1ed7f2c0dcefbfdebcb1816367246cc
crc32: B106D6FD
md5: 57ed22a50e7a067754f9acba247f272d
sha1: 22e09d30568c116f4482775d4efc1dc09ad455ad
sha256: a8e3bba3c2dfaf065448abde1245c636d1ed7f2c0dcefbfdebcb1816367246cc
sha512: 240f4ca2418567d71a1ac175b7e78024fb191bc2e40262a42f53f6386102164a9324973f73573c5098ff141a42a45e480d9312fc7e32b370236037ffc0135f05
ssdeep: 12288:htdibIjaGyFULCc6PHgtyQx8yShD2sUsZkyO79p6cFQ4aouXs:hu8oqH6PAt1JSDyn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3F4D13616B8F8D7D8392EF063136654982CA450FDB48A753609BC5B6DE0F734AF4B22
sha3_384: 450909ea754bfe3134775c34779d90edda02f9d63707896f20c88925511cfbffe4720a53d8641572119a1fcd870c14a4
ep_bytes: e8b9370000e979feffff8bff558bec83
timestamp: 2021-10-28 03:11:07

Version Info:

FileVersions: 65.26.95.52
InternationalName: polpwaoce.iwe
Copyright: Copyright (C) 2022, somoklos
ProjectsVersion: 60.25.78.9

Trojan:Win32/SmokeLoader.IJ!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Packed.4!c
AVGWin32:BotX-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.95317
ALYacTrojan.GenericKDZ.95317
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3987050
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059cbf41 )
AlibabaTrojan:Win32/SmokeLoader.65eb4ada
K7GWTrojan ( 0059cbf41 )
Cybereasonmalicious.50e7a0
VirITTrojan.Win32.Genus.NIV
CyrenW32/ABRisk.TMFD-7748
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HSAY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packer.pkr_ce1a-9980177-0
KasperskyHEUR:Trojan.Win32.Packed.gen
BitDefenderTrojan.GenericKDZ.95317
NANO-AntivirusTrojan.Win32.Kryptik.jvnarw
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:BotX-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
EmsisoftTrojan.GenericKDZ.95317 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.MulDrop21.28120
VIPRETrojan.GenericKDZ.95317
TrendMicroTROJ_GEN.R002C0DCF23
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.57ed22a50e7a0677
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.95317
JiangminTrojanRansom.Blocker.c
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=82)
Antiy-AVLTrojan[Backdoor]/Win32.Convagent
ArcabitTrojan.Generic.D17455
ViRobotTrojan.Win32.LockBit.410112
ZoneAlarmHEUR:Trojan.Win32.Packed.gen
MicrosoftTrojan:Win32/SmokeLoader.IJ!MTB
GoogleDetected
AhnLab-V3Trojan/Win.MalPe.X2055
McAfeeArtemis!57ED22A50E7A
VBA32Malware-Cryptor.InstallCore.5
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DCF23
RisingTrojan.Kryptik!8.8 (TFE:5:Q1NxhDWQyaR)
YandexTrojan.Kryptik!1E3ZycO63AM
IkarusTrojan.Win32.SmokeLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HSBL!tr
BitDefenderThetaAI:Packer.F0A32ED320
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/SmokeLoader.IJ!MTB?

Trojan:Win32/SmokeLoader.IJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment