Home Malware Programs Trojans Trojan.Downloader.Esaprof.A

Trojan.Downloader.Esaprof.A

Posted: December 24, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 1,260
First Seen: December 24, 2012
Last Seen: July 31, 2023
OS(es) Affected: Windows

Aliases

SWF/Agent.NDH!tr.dldr [Fortinet]Trojan-Downloader.Win32.Agent.wlvn [Kaspersky]Artemis!1DEF0CFCC696 [McAfee]TrojanDownloader.Esaprof [CAT-QuickHeal]Generic Malware [Panda]Dropper.Generic_c.MXB [AVG]SWF/Agent.NDG!tr.dldr [Fortinet]Win-Trojan/Esaprof.4717372 [AhnLab-V3]Trojan.Siggen4.10036 [DrWeb]UnclassifiedMalware [Comodo]Troj/Esaprof-A [Sophos]Trojan-Downloader.Win32.Agent.wouw [Kaspersky]Generic.lo [McAfee]Trojan.Agent.WD.cw3 [CAT-QuickHeal]Generic5.GQN [AVG]
More aliases (165)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\Alarm\Alarm.exe File name: Alarm.exe
Size: 299 KB (299008 bytes)
MD5: 61b63fe08d6f3a6514310e5950360fab
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Alarm\Alarm.exe
Group: Malware file
Last Updated: November 7, 2022
%APPDATA%\xx\xx\1.0.0.0\spoolsv.exe File name: spoolsv.exe
Size: 235.52 KB (235520 bytes)
MD5: 622c1b879e0ab5abcc3bcaa82c2bf746
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\xx\xx\1.0.0.0
Group: Malware file
Last Updated: December 26, 2012
%TEMP%\TMPprovider024.dll File name: TMPprovider024.dll
Size: 452.6 KB (452608 bytes)
MD5: 0c3ae22a2b7c196cea3b0a46c720c79f
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: December 26, 2012

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\Microsoft\Windows\Start Menu\Programs\0Photo.exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\20.exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Photo.exe

One Comment

  • scrapebox says:

    Hey there, You have done an incredible job. I'll certainly digg it and personally suggest to my friends. I am sure they'll be benefited from this web site.

Loading...