Trojan:Win32/SMSer.F removal tips

Malware Removal

The Trojan:Win32/SMSer.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Trojan:Win32/SMSer.F virus can do?

  • Executable code extraction
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/SMSer.F?


File Info:

crc32: 13B14BCE
md5: 06d972923892ee93ca6a86f7cee4e6cb
name: 06D972923892EE93CA6A86F7CEE4E6CB.mlw
sha1: a100a45e6b1b22ccad1bc7082600dbe7d6f8e07d
sha256: bdac1a0c8c70146cc7aeb4097a2e2fba55ccb29315faca0edf137b8d5ca3665a
sha512: 47201125092852c3345224b15f46a6d08d0bc72637b0e4cd4cc6bffb35693e9c424b3dc269393324e53c6c73d760a437cb833e699470d304997cc8687b613916
ssdeep: 96:gsxvprob++vLXCNQlXk+v4cJdHR7jnVj78qRu/yNGUODxmWUH1DVWVNpTOMdZB:gko7CNQlUaJnVHQ/yijUVDkj0MvB
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName:
FileVersion:
CompanyName:
ProductName:
OleSelfRegister:
ProductVersion:
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Trojan:Win32/SMSer.F also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Trojan.Heur.VP.amKfay6iVcpi
ALYacGen:Trojan.Heur.VP.amKfay6iVcpi
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
AegisLabTrojan.Win32.Generic.l5Bd
SangforTrojan.Win32.AGEN.1038553
K7AntiVirusTrojan ( 001003581 )
BitDefenderGen:Trojan.Heur.VP.amKfay6iVcpi
K7GWTrojan ( 001003581 )
Cybereasonmalicious.23892e
BitDefenderThetaAI:Packer.5346FB041F
CyrenW32/Risk.LKEG-8709
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.CH
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.PornoAsset.cral
AlibabaTrojan:Win32/PornoAsset.e9d01e1c
NANO-AntivirusTrojan.Win32.PornoAsset.edjatv
RisingRansom.PornoAsset!8.6AA (CLOUD)
Ad-AwareGen:Trojan.Heur.VP.amKfay6iVcpi
SophosMal/Generic-S
ComodoTrojWare.Win32.Autorun.JT@4zqndt
F-SecureTrojan.TR/Ransom.VB.AQ
DrWebTrojan.Winlock.407
ZillyaTrojan.FakeAV.Win32.7251
TrendMicroTROJ_RANSVB.SMA
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.xh
FireEyeGen:Trojan.Heur.VP.amKfay6iVcpi
EmsisoftGen:Trojan.Heur.VP.amKfay6iVcpi (B)
IkarusTrojan-Ransom.Fullscreen
JiangminTrojan.Chameleon.a
eGambitGeneric.Malware
AviraTR/Ransom.VB.AQ
MAXmalware (ai score=98)
Antiy-AVLTrojan[Ransom]/Win32.PornoAsset
MicrosoftTrojan:Win32/SMSer.F
ArcabitTrojan.Heur.VP.amKfay6iVcpi
ZoneAlarmTrojan-Ransom.Win32.PornoAsset.cral
GDataGen:Trojan.Heur.VP.amKfay6iVcpi
CynetMalicious (score: 100)
McAfeeArtemis!06D972923892
VBA32SScope.Trojan.Validium.va
MalwarebytesMalware.Heuristic.1003
PandaGeneric Malware
TrendMicro-HouseCallTROJ_RANSVB.SMA
TencentWin32.Trojan.Fullscreen.cpl
YandexTrojan.VB!wAyuuEADBV4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1020339.susgen
FortinetW32/Generic.AC.35333E!tr
WebrootTrojan:Win32/SMSer.F
AVGFileRepMalware
Qihoo-360Win32/Ransom.PornoAsset.HwsB4lkA

How to remove Trojan:Win32/SMSer.F?

Trojan:Win32/SMSer.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment