Home Malware Programs Keyloggers Smitfraud

Smitfraud

Posted: March 27, 2006

Threat Metric

Threat Level: 8/10
Infected PCs: 91
First Seen: July 24, 2009
Last Seen: October 31, 2022
OS(es) Affected: Windows

Smitfraud is a Trojan, which shows excessive pop-up messages showing a false alert or fake error message, trying to lure computer user into purchasing anti-spyware software, such as AdwareDelete, PSGuard, AntivirusGold or SpySheriff, that supposedly detects adware on your computer but in turn is a malicious spying software. Furthermore, Smitfraud replaces some Windows critical components with own infected files. Smitfraud is a malicious spyware and may cause serious system instability issues. It's recommended that you get rid of this trojan as soon as possible.

Aliases

Generic26.ZUH [AVG]Trojan/win32.agent.gen [Antiy-AVL]TR/Kazy.48076.5 [AntiVir]Gen:Variant.Kazy.48076 [BitDefender]MSIL:Dropper-RL [Drp] [Avast]a variant of MSIL/Injector.QA [NOD32]Trj/CI.A [Panda]Backdoor/Win32.Gbot [AhnLab-V3]Trojan.PWS.Siggen.31019 [DrWeb]Heur.Suspicious [Comodo]Gen:Variant.Kazy.48088 [BitDefender]Win32:Cycbot-PJ [Trj] [Avast]Backdoor [K7AntiVirus]Artemis!42376AD9EFEF [McAfee]Win32/Cryptor [AVG]
More aliases (119)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



drsmartload45a.exe File name: drsmartload45a.exe
Size: 28.02 KB (28024 bytes)
MD5: 44973d6051f7d0a88310866b3532f7e1
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
retadpu21.exe File name: retadpu21.exe
Size: 45.05 KB (45056 bytes)
MD5: 3933fa8deca73bd514e6ce3d934ee8a9
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
oembios32.dll File name: oembios32.dll
Size: 22.01 KB (22016 bytes)
MD5: e25c0e171d4122f36d0f7c7f67b4a9eb
Detection count: 94
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
retadpu1000106.exe File name: retadpu1000106.exe
Size: 45.05 KB (45056 bytes)
MD5: be5edac25bd1450060f93116ede6de88
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
wjiio.exe File name: wjiio.exe
Size: 38.21 KB (38216 bytes)
MD5: ddc57b76f71a82da9abc05ea00247a15
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
arpl.exe File name: arpl.exe
Size: 8.7 KB (8704 bytes)
MD5: 01604c6bc08f7dffbcc7d61b523704a5
Detection count: 53
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
drsmartload849a.exe File name: drsmartload849a.exe
Size: 28.67 KB (28672 bytes)
MD5: d471f4ffd83dc95df6d63076dcdf6cc1
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
services.exe File name: services.exe
Size: 118.27 KB (118272 bytes)
MD5: d85e078fed9ce534fa5e2ef999955955
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
byxusss.dll File name: byxusss.dll
Size: 31.25 KB (31254 bytes)
MD5: 8cef9f4bb684f88e419f5de46e289bc2
Detection count: 40
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
drsmartload45a.exe File name: drsmartload45a.exe
Size: 28.67 KB (28672 bytes)
MD5: d90333f18e27c218cf7efd2b1a30212a
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
csrss.exe File name: csrss.exe
Size: 103.42 KB (103424 bytes)
MD5: f7f18b92a3d6f169b05d95cef3e01d37
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
atmtd.dll File name: atmtd.dll
Size: 687.59 KB (687592 bytes)
MD5: 6d5f90ea52fe0cdc102b14485563eba0
Detection count: 32
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
drsmartload46a.exe File name: drsmartload46a.exe
Size: 28.67 KB (28672 bytes)
MD5: d9f95415d24dee922ad9748e918a9363
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
MTE3NDI6ODoxNg.exe File name: MTE3NDI6ODoxNg.exe
Size: 25.1 KB (25105 bytes)
MD5: f7212a74bcec46b93283656ccd886af0
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2022
%APPDATA%\21.exe File name: 21.exe
Size: 220.16 KB (220160 bytes)
MD5: 49b9be7bcd5826cad36d7dfc9b05dedc
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 15, 2020
ssqnool.dll File name: ssqnool.dll
Size: 31.25 KB (31254 bytes)
MD5: f62114fa101cca85d3764369f0619a1c
Detection count: 4
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
cvajjkohifjam.exe File name: cvajjkohifjam.exe
Size: 33.23 KB (33232 bytes)
MD5: f1f06bee214b2748e7b6b8d189c92370
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
akylrvamqzjn.exe File name: akylrvamqzjn.exe
Size: 30.79 KB (30792 bytes)
MD5: 280bdc03f8f964e4c91d6ea1f6e61168
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
retadpu.exe File name: retadpu.exe
Size: 45.05 KB (45056 bytes)
MD5: 5a6b91738dfa140b59ff1b7c36bdf2de
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
drsmartload1.exe File name: drsmartload1.exe
Size: 28.67 KB (28672 bytes)
MD5: 5bb95c9cf7aa0c066c9667be6e7e64c4
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{27321538-5739-4aa1-b84c-7d18e4383f1f}File name without pathdrsmartload2.dat

Related Posts

Loading...