Home Malware Programs Trojans Trojan.Egguard

Trojan.Egguard

Posted: April 23, 2016

Threat Metric

Ranking: 19,890
Threat Level: 8/10
Infected PCs: 260,245
First Seen: April 23, 2016
Last Seen: January 26, 2025
OS(es) Affected: Windows

Trojan.Egguard is a malicious parasite that may evade a computer through random malicious scripts or injections found over the Internet or by a questionable downloaded file. When installed, Trojan.Egguard may run in the background going undetected for extended periods of time. Additionally, Trojan.Egguard may add several malicious files within various locations of the infected PC's hard drive. Many of the files associated with Trojan.Egguard are random DLL (Dynamic Link Library) files and various registry entries that may act to allow remote access for a hacker. If not removed, Trojan.Egguard may be a gateway for remote attackers to access the infected computer. It is imperative that Trojan.Egguard is detected and eliminated by the use of the necessary antimalware resources. Allowing Trojan.Egguard to run on a system is encouraging to remote attackers to infiltrate the infected computer, which may later lead to theft of personal data causing identity theft or other serious issues.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\ProgramData\Microsoft\Windows\EventSvc\work0.exe.bak File name: work0.exe.bak
Size: 4.36 MB (4364800 bytes)
MD5: ed27f55b0b3fb1445d4c17ab515a0590
Detection count: 19,297
Mime Type: unknown/bak
Path: C:\ProgramData\Microsoft\Windows\EventSvc\work0.exe.bak
Group: Malware file
Last Updated: February 19, 2023
C:\zv\outbox\018028.EXE File name: 018028.EXE
Size: 1.26 MB (1265664 bytes)
MD5: 201d738546fa9be8450c51b84fae14d8
Detection count: 2,656
File type: Executable File
Mime Type: unknown/EXE
Path: C:\zv\outbox\018028.EXE
Group: Malware file
Last Updated: July 20, 2021
C:\ProgramData\Microsoft\Windows\EventSvc\work0.exe File name: work0.exe
Size: 4.36 MB (4364800 bytes)
MD5: 591b28799acdd2ed71aa3da89310f139
Detection count: 2,438
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\Microsoft\Windows\EventSvc
Group: Malware file
Last Updated: February 15, 2021
C:\ProgramData\Windows Security\f\up\Bk17_20_870\winsecurity.exe File name: winsecurity.exe
Size: 1.37 MB (1376256 bytes)
MD5: 4404d5b7a40830680971e73a18a287cc
Detection count: 639
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\Windows Security\f\up\Bk17_20_870\winsecurity.exe
Group: Malware file
Last Updated: December 6, 2022
%ALLUSERSPROFILE%\MiniFriv00.exe File name: MiniFriv00.exe
Size: 1.27 MB (1274368 bytes)
MD5: dae2585a3ab5d69ddbf7f214def540cd
Detection count: 319
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 30, 2016
C:\ProgramData\MiniFriv_Egg37_Setup.exe File name: MiniFriv_Egg37_Setup.exe
Size: 795.68 KB (795683 bytes)
MD5: cf870e15ddef75ea1293214b2952f8b0
Detection count: 300
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\MiniFriv_Egg37_Setup.exe
Group: Malware file
Last Updated: August 2, 2022
%ALLUSERSPROFILE%\Microsoft\Network\Downloader\downloader.exe File name: downloader.exe
Size: 70.3 KB (70305 bytes)
MD5: 733066fe7939d9b04f320366cd558292
Detection count: 258
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Network\Downloader
Group: Malware file
Last Updated: June 1, 2016
C:\zv\outbox\007020.EXE File name: 007020.EXE
Size: 8.08 MB (8084992 bytes)
MD5: ceb07dd7e9804292df90a0ccc582b53c
Detection count: 197
File type: Executable File
Mime Type: unknown/EXE
Path: C:\zv\outbox\007020.EXE
Group: Malware file
Last Updated: December 4, 2021
%ALLUSERSPROFILE%\Microsoft\Network\Dsq\browser\syshostctl.exe File name: syshostctl.exe
Size: 178.68 KB (178688 bytes)
MD5: 35db0e95abc4ef3d01a0d6cb01f83cdd
Detection count: 178
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Network\Dsq\browser
Group: Malware file
Last Updated: August 3, 2022
%ALLUSERSPROFILE%\MiniFriv02.exe File name: MiniFriv02.exe
Size: 1.27 MB (1274368 bytes)
MD5: 53079260055897db2a8d9a35ae1be15a
Detection count: 166
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 30, 2016
%PROGRAMFILES(x86)%\SkypeUpdateEx\SkypeUpdateEx.exe File name: SkypeUpdateEx.exe
Size: 171.95 KB (171952 bytes)
MD5: ab02823701fe46acef4f7425f5d28992
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SkypeUpdateEx
Group: Malware file
Last Updated: June 8, 2016
%ALLUSERSPROFILE%\Microsoft\Network\Dsq\network\sysnetwk.exe File name: sysnetwk.exe
Size: 6.67 MB (6671360 bytes)
MD5: dcb6b84a4f60eb7bf8c9a1fb9588857d
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Network\Dsq\network
Group: Malware file
Last Updated: August 3, 2022
%WINDIR%\EProtect_x86.sys File name: EProtect_x86.sys
Size: 17.29 KB (17296 bytes)
MD5: b9c4a3c5b55317ef5fbd988d36d12321
Detection count: 43
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%
Group: Malware file
Last Updated: August 19, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\Microsoft\Network\Dsq\browser\syshostctl.exe%ALLUSERSPROFILE%\Microsoft\Network\Dsq\network\sysnetwk.exe%ALLUSERSPROFILE%\microsoft\windows\eventsvc\eventsvc.exe%ALLUSERSPROFILE%\Microsoft\Windows\EventSvc\work0.exe%ALLUSERSPROFILE%\Microsoft\Windows\GPR\browser\svchostctl.exe%ALLUSERSPROFILE%\Windows Security\winsecurity.exe%WINDIR%\EUtil_amd64.sys%WINDIR%\EUtil_x86.sys

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\Microsoft\Network\Dsq%ALLUSERSPROFILE%\EventSvc%ALLUSERSPROFILE%\Microsoft\Network\Dsq%PROGRAMFILES%\SkypeUpdateEx%PROGRAMFILES(x86)%\SkypeUpdateEx
Loading...