Trojan

Trojan:Win32/SmokeLoader!pz removal tips

Malware Removal

The Trojan:Win32/SmokeLoader!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SmokeLoader!pz virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/SmokeLoader!pz?


File Info:

name: ED347B4606E6E8195784.mlw
path: /opt/CAPEv2/storage/binaries/02a4d5373c036652b58bb7587ba6b5267fee472b1d15bb837fee65df3233e141
crc32: 955FC8BC
md5: ed347b4606e6e8195784c2389e9b96f4
sha1: 4473f7a50acf7756ca73b52903ea47922f2c0a62
sha256: 02a4d5373c036652b58bb7587ba6b5267fee472b1d15bb837fee65df3233e141
sha512: 5585acdfc6fe5103c0aa8353d9ec2c4c984cd28559f7f556ffc26b65487968185ff48b4cb7a0db63a6928190542a599d93683f0e1bb50a036bcfd98d392db6a2
ssdeep: 3072:s1whbB064LDjA0Xd/cmwmdttl14jkH7aMxjTwu7jK:fbBUlFcmwm5gY7ZPBj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A264C2382F17D84FA35CB729E2ECAEC76DEF6508F09776A21589A1F04B11B2C563711
sha3_384: 8725ab0a3202fff07fec9e0abba76e044beb4d90ae20719beadf61dbe188efa3073cd28e5c4e4140027560794eb0f8ab
ep_bytes: 0c908e90018e686bb12e68dcf8656565
timestamp: 2023-11-23 12:48:36

Version Info:

0: [No Data]

Trojan:Win32/SmokeLoader!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.SmokeLoader.m!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.655877
FireEyeGeneric.mg.ed347b4606e6e819
SkyhighArtemis!Trojan
ALYacGen:Variant.Razy.655877
Cylanceunsafe
ZillyaTrojan.Smokeloader.Win32.6283
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057769f1 )
AlibabaTrojan:Win32/SmokeLoader.d16e0462
K7GWTrojan ( 0057769f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.B30AF7371F
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Smokeloader
ESET-NOD32a variant of Win32/Smokeloader.F
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packer.pkr_ce1a-9980177-0
KasperskyUDS:Backdoor.Win32.Mokes
BitDefenderGen:Variant.Razy.655877
NANO-AntivirusTrojan.Win32.Mokes.kenzoc
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Crypt.Mzfl
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Razy.655877
TrendMicroTROJ_GEN.R03BC0DLO23
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.655877 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/SmokeLoader.G.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.SmokeLoader
MicrosoftTrojan:Win32/SmokeLoader!pz
GridinsoftTrojan.Win32.SmokeLoader.sa
ArcabitTrojan.Razy.DA0205
ViRobotTrojan.Win.Z.Smokeloader.4591616.A
ZoneAlarmUDS:Backdoor.Win32.Mokes
GDataGen:Variant.Razy.655877
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5556219
McAfeeArtemis!ED347B4606E6
MAXmalware (ai score=87)
MalwarebytesTrojan.SmokeLoader
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DLO23
RisingTrojan.SmokeLoader!1.E9FD (CLASSIC)
YandexBackdoor.Mokes!N0/AbjkYQKM
IkarusTrojan.Win32.SmokeLoader
MaxSecureTrojan.Malware.73415445.susgen
FortinetW32/Smokeloader.F!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.50acf7
DeepInstinctMALICIOUS

How to remove Trojan:Win32/SmokeLoader!pz?

Trojan:Win32/SmokeLoader!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment