Trojan

Trojan:Win32/SmokeLoader.SBR!MSR removal guide

Malware Removal

The Trojan:Win32/SmokeLoader.SBR!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SmokeLoader.SBR!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Georgian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

vaggner.uno
sfirza.best
historychina.best
chinabuild.uno

How to determine Trojan:Win32/SmokeLoader.SBR!MSR?


File Info:

crc32: 0A7EED3E
md5: 8687374122af400f27fa9d6aac9aef8f
name: client.exe
sha1: 12c9d643e214d91302c1d268067464f7db2a13c4
sha256: 54cee778511f57fc4a218fe5fa59e604af2d38fece424c01261a44e9a6adc0d0
sha512: 82901bd3d2b8b573e47c43d9ea6952fa251c52e2746616f34439ac43ceaefd6f0e425ff393a713bfb912d59d5b6984cf2f0f30717b71a908660dc77cb0dea039
ssdeep: 1536:bpzZS7WIaUXXuArIb19OGZkpfRK9V2lgJnMX4zOq7HjydQkVBhyBMUY8saQVsPH:bpzxIam+TOY2lHrOkVDMMUY8sXVsPH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sdoxfbok.uda
FileVersion: 1.2.9

Trojan:Win32/SmokeLoader.SBR!MSR also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34366007
FireEyeGeneric.mg.8687374122af400f
CAT-QuickHealTrojan.Inject.22252
ALYacTrojan.GenericKD.34366007
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0056c9681 )
BitDefenderTrojan.GenericKD.34366007
K7GWTrojan ( 0056c9681 )
Cybereasonmalicious.3e214d
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Glupteba-9355901-0
KasperskyExploit.Win32.Shellcode.spa
AlibabaExploit:Win32/Shellcode.ebb2d5a3
TencentWin32.Exploit.Shellcode.Eaxb
Ad-AwareTrojan.GenericKD.34366007
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Crypt.Agent.oslzi
TrendMicroTROJ_FRS.VSNW10H20
SophosMal/Kryptik-EA
SentinelOneDFI – Malicious PE
JiangminExploit.ShellCode.afa
AviraTR/Crypt.Agent.oslzi
MicrosoftTrojan:Win32/SmokeLoader.SBR!MSR
ArcabitTrojan.Generic.D20C6237
ZoneAlarmExploit.Win32.Shellcode.spa
GDataTrojan.GenericKD.34366007
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Tofsee.R348129
Acronissuspicious
McAfeePacked-GAO!8687374122AF
MAXmalware (ai score=100)
VBA32BScope.Adware.Caypnamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFNK
TrendMicro-HouseCallTROJ_FRS.VSNW10H20
RisingTrojan.Kryptik!1.CA8B (CLOUD)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_89%
FortinetW32/GenKryptik.EQFR!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Exploit.b01

How to remove Trojan:Win32/SmokeLoader.SBR!MSR?

Trojan:Win32/SmokeLoader.SBR!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment