SMRSS.EXE – Trojan Dadobra

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SMRSS.EXE – Trojan Dadobra removal

FileMD5Virus Alias
SMRSS.EXE 0eeb7a11d704b5db187920346835ddbf Trojan Dadobra
SMRSS.EXE 0eeb7a11d704b5db187920346835ddbf Trojan SuspiciousFile
SMRSS.EXE 0eeb7a11d704b5db187920346835ddbf Trojan Eldorado
SMRSS.EXE 0eeb7a11d704b5db187920346835ddbf Trojan Downloader
SMRSS.EXE 0eeb7a11d704b5db187920346835ddbf Trojan Agent
SMRSS.EXE 0eeb7a11d704b5db187920346835ddbf Trojan Delf

SMRSS.EXE size: 431862 bytes
SMRSS.EXE hash: 0EEB7A11D704B5DB187920346835DDBF

Created files:

%WinDir%\svchost.exe
%SysDir%\freizer.exe
%SysDir%\smrss.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\freizer: %WinDir%\System32\freizer.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchost: %WinDir%\System32\svchost.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe smrss.exe

Detected by UnHackMe:

SMRSS.EXE
Default location: %SYSDIR%\SMRSS.EXE

Dropper information:
MD5: 0eeb7a11d704b5db187920346835ddbf
File size: 431862 bytes

Leave a Reply