Solved! Use SMRSS.EXE (Trojan Dadobra) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SMRSS.EXE – Trojan Dadobra removal

FileMD5Virus Alias
SMRSS.EXE 2c9144f7b63cd5f2f6bea074fc4f2a36 Trojan Dadobra
SMRSS.EXE 2c9144f7b63cd5f2f6bea074fc4f2a36 Trojan SuspiciousFile
SMRSS.EXE 2c9144f7b63cd5f2f6bea074fc4f2a36 Trojan Eldorado
SMRSS.EXE 2c9144f7b63cd5f2f6bea074fc4f2a36 Trojan Downloader
SMRSS.EXE 2c9144f7b63cd5f2f6bea074fc4f2a36 Trojan OnLineGames
SMRSS.EXE 2c9144f7b63cd5f2f6bea074fc4f2a36 Trojan Agent

SMRSS.EXE size: 1041214 bytes
SMRSS.EXE hash: 2C9144F7B63CD5F2F6BEA074FC4F2A36

Created files:

%WinDir%\svchost.exe
%SysDir%\freizer.exe
%SysDir%\smrss.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\freizer: %WinDir%\System32\freizer.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchost: %WinDir%\System32\svchost.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe smrss.exe

Detected by UnHackMe:

SMRSS.EXE
Default location: %SYSDIR%\SMRSS.EXE

Dropper information:
MD5: 2c9144f7b63cd5f2f6bea074fc4f2a36
File size: 1041214 bytes

Leave a Reply