Home Malware Programs Worms Esfury.T

Esfury.T

Posted: March 6, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 185
First Seen: March 6, 2011
Last Seen: March 15, 2022
OS(es) Affected: Windows

Aliases

Generic Trojan [Panda]Generic28.PNJ [AVG]W32/ZedoPoo.IO!tr [Fortinet]Trojan/Win32.Buzus.gen [Antiy-AVL]Worm/Esfury.T.3 [AntiVir]Trojan-Ransom.Win32.ZedoPoo.io [Kaspersky]Win32:Esfury-H [Trj] [Avast]probably a variant of Win32/Autorun.ESDVVZG [NOD32]Trojan [K7AntiVirus]Ransom!fp [McAfee]TrojanRansom.ZedoPoo.io [CAT-QuickHeal]Generic22.NGA [AVG]W32/VB.ARHO!tr [Fortinet]Mal/Generic-L [Sophos]TR/Spy.66048.41 [AntiVir]
More aliases (95)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\program files (x86)\common files\boonty shared\service\boonty.exe File name: boonty.exe
Size: 69.12 KB (69120 bytes)
MD5: 37b2c72827ae953ea03e94d763bb9ac0
Detection count: 117
File type: Executable File
Mime Type: unknown/exe
Path: c:\program files (x86)\common files\boonty shared\service\boonty.exe
Group: Malware file
Last Updated: February 20, 2022
%WINDIR%\system32\config\systemprofile\CROW2004\Local Settings\Application Data\wins.exe File name: wins.exe
Size: 4.92 MB (4928512 bytes)
MD5: ce4a6f87e79274e724b450bbb42ef2aa
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\config\systemprofile\CROW2004\Local Settings\Application Data
Group: Malware file
Last Updated: March 7, 2011
%USERPROFILE%\27F6471627473796E696D64614\winlogon.exe File name: winlogon.exe
Size: 106.49 KB (106496 bytes)
MD5: 46795b941aba627d9c799a9840c74ee3
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\27F6471627473796E696D64614
Group: Malware file
Last Updated: February 11, 2013
%WINDIR%\System32\drivers\sstA35.sys File name: sstA35.sys
Size: 82.94 KB (82944 bytes)
MD5: 694f1d8c84c973e3f89a3c4b0cdb9b1b
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: March 14, 2011

More files
Loading...