smith32.exe

The executable smith32.exe has been detected as malware by 22 anti-virus scanners. According to AVG, this software downloads additional adware offers during setup.
MD5:
5078f4ab31d2bac0ec56f0b295ed6a49

SHA-1:
c3e90bcc487955d89499a865f588e247797bc376

SHA-256:
dcdecf9c7b8483427026dee031ea7cb707aa2cb3f59b02c161856ababa79e691

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
4/1/2025 7:17:44 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Spy.Banker.Gen
7.11.25.42

avast!
Win32:Spyware-gen [Spy]
2014.9-170316

AVG
Downloader.Generic12
2018.0.2438

Bitdefender
Trojan.Generic.KD.542976
1.0.20.375

Comodo Security
UnclassifiedMalware
11774

Emsisoft Anti-Malware
Trojan-PWS.Win32.Tibia!IK
8.17.03.16.12

ESET NOD32
Win32/Spy.Banker.XKK
11.6961

Fortinet FortiGate
W32/Banker.XKK!tr.spy
3/16/2017

F-Secure
Trojan.Generic.KD.542976
11.2017-16-03_5

G Data
Trojan.Generic.KD.542976
17.3.22

IKARUS anti.virus
Trojan-PWS.Win32.Tibia
t3scan.1.1.118.0

K7 AntiVirus
Trojan-Downloader
13.133.6404

Kaspersky
Trojan-Downloader.Win32.Delf
14.0.0.-1315

McAfee
Artemis!5078F4AB31D2
5600.6094

Norman
W32/Suspicious_Gen4.QCYL
11.20170316

nProtect
Trojan/W32.Agent.1108992.M
12.03.12.01

Panda Antivirus
Generic Malware
17.03.16.12

Quick Heal
TrojanDownloader.Delf.begl
3.17.12.00

Trend Micro House Call
TSPY_BANKER.MJSM
7.2.75

Trend Micro
TSPY_BANKER.MJSM
10.465.16

Vba32 AntiVirus
TrojanDownloader.Delf.hlvz
3.12.16.4

VIPRE Antivirus
Trojan-Downloader.Win32.Delf
11656

File size:
1.1 MB (1,108,992 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\win78aef6ce\smith32.exe

File PE Metadata
Compilation timestamp:
2/21/2012 1:20:18 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xEAD04

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 4C, 32, 4E, 00, E8, 2B, F4, F1, FF, 8B, 1D, 64, D3, 4E, 00, 8B, 03, E8, 16, DC, FB, FF, 8B, 03, B2, 01, E8, 49, F9, FB, FF, 8B, 0D, DC, D3, 4E, 00, 8B, 03, 8B, 15, D8, 27, 4E, 00, E8, 12, DC, FB, FF, 8B, 0D, F8, D3, 4E, 00, 8B, 03, 8B, 15, 28, 1A, 4E, 00, E8, FF, DB, FB, FF, 8B, 0D, 2C, D3, 4E, 00, 8B, 03, 8B, 15, 5C, 13, 4E, 00, E8, EC, DB, FB, FF, 8B, 03, E8, 35, DD, FB, FF, 5B, E8, 9F, B1, F1, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
932 KB (954,368 bytes)

Remove smith32.exe - Powered by Reason Core Security