Home Malware Programs Worms Esfury.T

Esfury.T

Posted: March 6, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 185
First Seen: March 6, 2011
Last Seen: March 15, 2022
OS(es) Affected: Windows

Aliases

Generic Trojan [Panda]Generic28.PNJ [AVG]W32/ZedoPoo.IO!tr [Fortinet]Trojan/Win32.Buzus.gen [Antiy-AVL]Worm/Esfury.T.3 [AntiVir]Trojan-Ransom.Win32.ZedoPoo.io [Kaspersky]Win32:Esfury-H [Trj] [Avast]probably a variant of Win32/Autorun.ESDVVZG [NOD32]Trojan [K7AntiVirus]Ransom!fp [McAfee]TrojanRansom.ZedoPoo.io [CAT-QuickHeal]Generic22.NGA [AVG]W32/VB.ARHO!tr [Fortinet]Mal/Generic-L [Sophos]TR/Spy.66048.41 [AntiVir]
More aliases (95)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\program files (x86)\common files\boonty shared\service\boonty.exe File name: boonty.exe
Size: 69.12 KB (69120 bytes)
MD5: 37b2c72827ae953ea03e94d763bb9ac0
Detection count: 117
File type: Executable File
Mime Type: unknown/exe
Path: c:\program files (x86)\common files\boonty shared\service\boonty.exe
Group: Malware file
Last Updated: February 20, 2022
%USERPROFILE%\27F6461627473796E696D64614\winlogon.exe File name: winlogon.exe
Size: 64 KB (64000 bytes)
MD5: 63ad78921e2a71f4961ad252bd47738a
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\27F6461627473796E696D64614
Group: Malware file
Last Updated: March 6, 2011
%USERPROFILE%\27F6471627473796E696D64614\winlogon.exe File name: winlogon.exe
Size: 106.49 KB (106496 bytes)
MD5: 46795b941aba627d9c799a9840c74ee3
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\27F6471627473796E696D64614
Group: Malware file
Last Updated: February 11, 2013
Loading...