SMRSS.EXE – Trojan Dadobra

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SMRSS.EXE – Trojan Dadobra removal

FileMD5Virus Alias
SMRSS.EXE 17ef6f26a6f0b667bc5001a892edb5ca Trojan Dadobra
SMRSS.EXE 17ef6f26a6f0b667bc5001a892edb5ca Trojan SuspiciousFile
SMRSS.EXE 17ef6f26a6f0b667bc5001a892edb5ca Trojan Eldorado
SMRSS.EXE 17ef6f26a6f0b667bc5001a892edb5ca Trojan Downloader
SMRSS.EXE 17ef6f26a6f0b667bc5001a892edb5ca Trojan OnLineGames
SMRSS.EXE 17ef6f26a6f0b667bc5001a892edb5ca Trojan Agent

SMRSS.EXE size: 1000608 bytes
SMRSS.EXE hash: 17EF6F26A6F0B667BC5001A892EDB5CA

Created files:

%WinDir%\svchost.exe
%SysDir%\freizer.exe
%SysDir%\smrss.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\freizer: %WinDir%\System32\freizer.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchost: %WinDir%\System32\svchost.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe smrss.exe

Detected by UnHackMe:

SMRSS.EXE
Default location: %SYSDIR%\SMRSS.EXE

Dropper information:
MD5: 17ef6f26a6f0b667bc5001a892edb5ca
File size: 1000608 bytes

Leave a Reply