SMSS.EXE – Backdoor Maximus

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SMSS.EXE – Backdoor Maximus removal

FileMD5Virus Alias
SMSS.EXE 15ba2fe82d734a42c04affb3275b074e Backdoor Maximus
SMSS.EXE 15ba2fe82d734a42c04affb3275b074e Trojan Agent
SMSS.EXE 15ba2fe82d734a42c04affb3275b074e Trojan Small
SMSS.EXE 15ba2fe82d734a42c04affb3275b074e Trojan Invader

SMSS.EXE size: 360680 bytes
SMSS.EXE hash: 15BA2FE82D734A42C04AFFB3275B074E

Created files:

C:\Explorer\Folder.htt
C:\Explorer\Launch_U3.exe
C:\Explorer\msvbvm60.dll
C:\LaunchU3systemprofile.exe
%WinDir%\msvbvm60.dll
%UserProfile%\Local Settings\Application Data\WINDOWS\CSRSS.EXE
%UserProfile%\Local Settings\Application Data\WINDOWS\SERVICES.EXE
%UserProfile%\Local Settings\Application Data\WINDOWS\SMSS.EXE
%SysDir%\msvbvm60.dll
%SysDir%\shell.exe
%SysDir%\Telematika.scr
%WinDir%\WlNLOGON.EXE
C:\WlNLOGON.EXE

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\LogonSystemprofile: %Local AppData%\WINDOWS\CSRSS.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\System Monitoring: %Local AppData%\WINDOWS\SMSS.EXE
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe “%WinDir%\System32\Shell.exe”
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: %WinDir%\System32\userinit.exe,%WinDir%\System32\Shell.exe
HKCU\Control Panel\Desktop\SCRNSAVE.EXE: %WinDir%\System32\TELEMA~1.SCR
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Depkominfo: %WinDir%\WlNLOGON.EXE
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ServiceSystemprofile: %Local AppData%\WINDOWS\SERVICES.EXE

Detected by UnHackMe:

SMSS.EXE
Default location: %LOCAL APPDATA%\WINDOWS\SMSS.EXE

Dropper information:
MD5: 0aa16f7139ae1ab16de3705f1c77bf54
File size: 360680 bytes

Leave a Reply