Trojan

Trojan:Win32/SmokeLoader!pz removal guide

Malware Removal

The Trojan:Win32/SmokeLoader!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SmokeLoader!pz virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/SmokeLoader!pz?


File Info:

name: A0C0A6279199EC8A13ED.mlw
path: /opt/CAPEv2/storage/binaries/0b7dfe7468f4fc1ea376d1c8d855181ee5880f6e4468f1a3c9e9e7923c06099e
crc32: A3B86CFA
md5: a0c0a6279199ec8a13ed2feae4d32d8b
sha1: f00501408e6a9e9d0839b49ff9ac261765b78e68
sha256: 0b7dfe7468f4fc1ea376d1c8d855181ee5880f6e4468f1a3c9e9e7923c06099e
sha512: 615d0a4622c9dd52b56e9caeeefbab59987e6802f984a5597cee78446c9964f9320ed719fda29cc02960ca26d142c71bf0adca437debeeeb6dfc6b9526d82740
ssdeep: 3072:sywhbBLXvoaEXJiu/TQqhTSC95sz46dXJAHdgjgJSn3/QL55DcJD4rle6qjG:qbBLQLDjbYz46d5A9f4n3GE4rll
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E164AE1179F8D431E2F7193654B0C7E40A7FB862F835994FAAC42BAD9E347D19A2130B
sha3_384: ee632281aa7c9d8773ddc3e6d82a2de764d553459f59936ca27506cf2a10cddcf02ef10c978cc07135a4676f80746c4c
ep_bytes: 0c908e90018e686bb12e68dcf8656565
timestamp: 2023-11-23 12:48:36

Version Info:

0: [No Data]

Trojan:Win32/SmokeLoader!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.SmokeLoader.m!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.655877
ClamAVWin.Packed.Smokeloader-10016651-0
FireEyeGeneric.mg.a0c0a6279199ec8a
SkyhighBehavesLike.Win32.Generic.fh
ALYacGen:Variant.Razy.655877
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057769f1 )
AlibabaBackdoor:Win32/Mokes.6bab78ba
K7GWTrojan ( 0057769f1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Razy.DA0205
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Smokeloader
ESET-NOD32a variant of Win32/Smokeloader.F
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Mokes.asfm
BitDefenderGen:Variant.Razy.655877
NANO-AntivirusTrojan.Win32.Mokes.kenzoc
AvastFileRepMalware [Pws]
TencentWin32.Backdoor.Mokes.Adhl
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Razy.655877
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.655877 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.SmokeLoader
KingsoftWin32.Hack.Mokes.asfm
MicrosoftTrojan:Win32/SmokeLoader!pz
ZoneAlarmBackdoor.Win32.Mokes.asfm
GDataGen:Variant.Razy.655877
VaristW32/SmokeLoader.G.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5556219
McAfeeArtemis!A0C0A6279199
MAXmalware (ai score=86)
MalwarebytesTrojan.SmokeLoader
TrendMicro-HouseCallTROJ_GEN.R03BC0DLV23
RisingTrojan.SmokeLoader!1.E9FD (CLASSIC)
YandexBackdoor.Mokes!N0/AbjkYQKM
IkarusTrojan.Win32.SmokeLoader
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Smokeloader.F!tr
BitDefenderThetaAI:Packer.652225511E
AVGFileRepMalware [Pws]
Cybereasonmalicious.08e6a9
DeepInstinctMALICIOUS

How to remove Trojan:Win32/SmokeLoader!pz?

Trojan:Win32/SmokeLoader!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment