SMDAT32M.SYS
What you should do about SMDAT32M.SYS:
The most common objects with the name of SMDAT32M.SYS have yet to be classified as safe by our research department.
If you are concerned that your PC might be infected why not try our Free version of Prevx 3.0. It will thoroughly check your PC for millions of active Spyware and malware infections and takes less than 2 minutes. Don't take the risk, check your PC now.
What we know about SMDAT32M.SYS:
SMDAT32M.SYS
AUTOMATED MALWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION:
DEFINITION OF: SMDAT32M.SYS
- Safety Rating: Known Malware, do not run
- Malware Family: Part of Malware group - Malware
- Malware Form: EXPLOIT
- Protection: Prevx provides powerful security products that you can use to detect, remove and protect you from SMDAT32M.SYS and safeguard your PC against viruses, trojans, worms, spyware, rootkits and adware
- Why risk having spyware on your PC when it takes less than 2 minutes to thoroughly check it with Prevx CSI? Click here to check your PC with Prevx CSI Now.
- First seen: Jul 15 2005 (GMT)
- Last seen: Jul 15 2005 (GMT)
- File Size: 330,240 bytes
MALWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY
1. COVERT ANALYSIS OF: SMDAT32M.SYS
- File Names Used: 328
- Paths Used: 779
- Common File Name: SMDAT32M.SYS
- Common Path: %PROGRAMFILES%\ALTNET\DOWNLOAD MANAGER\
- Vendor Information: No Vendor details specified
- Product Information: Altnet Sharing Manager
- Version Information: 1, 0, 0, 0
- SMDAT32M.SYS may use 328 or more path and file names, these are the most common:
- 1 :%DESKTOP%\TEST\9C9A09A700807134C0870B19BB37.....EXE
- 2 :%profiles%\hervé ducreux\local settings\temp\FNB626EB7D.EXE
- 3 :%temp%\{483b4568-a6a0-4d56-83f9-759a2fbe0dfe}\ASM10.EXE
- 4 :%TEMP%\FN25BE19DB.EXE
- 5 :%TEMP%\FN34AD407A.EXE
- 6 :%TEMP%\FN36803735.EXE
- 7 :%TEMP%\FNA03964.EXE
- 8 :%TEMP%\FNAC464A65.EXE
- 9 :?:\A00000000
- File Name Structure: Normal
- File and Path Structure: Suspicious, unusually high number of file and path combinations
2. RELATIONSHIP ANALYSIS OF: SMDAT32M.SYS
- Malicious Objects Created: 1 objects
- Malicious Creators: 12
- Malware Run Keys: Has registry run keys created by known malware objects
- Self Persists:
- Antivirus Detection: Yes, detected by one or more 3rd party Antivirus product
- Anti-Spyware Detection: Yes, detected by one or more 3rd party Anti-Spyware product
3. ACTIVITY ANALYSIS OF: SMDAT32M.SYS
- The following behaviors have been observed for this object:
- Installs programs.
- Deletes programs.
- Invokes dll components.
- Modifies the hostsfile.
- Runs temporary programs.
- Runs other programs.
- Communicates with web sites using httpout protocols.
- Scans active processes.
- Hijacks running processes.
- Has outbound communications.
- Inspects email address books.
- Creates registry entries.
- Creates known malware.
- Sends Mime Emails.
4. PROPAGATION ANALYSIS OF: SMDAT32M.SYS
- Malware Group Propagation Rate: Moderate (spreading)
- Malware Group: Malware
- Copyright Prevx Limited 2005, 2006
