Threat Database Trojans Trojan.ArchSMS

Trojan.ArchSMS

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 16,756
Threat Level: 80 % (High)
Infected Computers: 1,017
First Seen: September 21, 2011
Last Seen: September 11, 2025
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.ArchSMS

File System Details

Trojan.ArchSMS may create the following file(s):
# File Name MD5 Detections
1. start.exe 262bea6bc12282cde3fb4010dc9b31f2 26
2. OSFirewall.exe 494cc484233a807b4fd93bf2c90a2741 13
3. update.exe 045578eb6f48410a93e040ecc0908c2e 1
More files

Registry Details

Trojan.ArchSMS may create the following registry entry or registry entries:
Regexp file mask
%APPDATA%\Microsoft\OSFirewall.exe

Analysis Report

General information

Family Name: Trojan.ArchSMS
Signature status: Root Not Trusted

Known Samples

MD5: 977cb302f626cec8c61597e651345820
SHA1: 527689778406f5db5b5eb92aa2ce0d46346f601a
SHA256: 7F37FFB54F6CA3501834D517CF513890B528BF2C90830250469B23F7AEC3AB03
File Size: 277.98 KB, 277976 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Digital Signatures

Signer Root Status
BERNEX APLICACIONES SL Go Daddy Class 2 Certification Authority Root Not Trusted

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsc5f49.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk59ba.tmp\logo.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk59ba.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk59ba.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk59ba.tmp\nsisdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk59ba.tmp\system.dll Generic Write,Read Attributes

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • inet_addr
  • socket

Trending

Most Viewed

Loading...