Home Malware Programs Trojans Trojan.Necurs.A

Trojan.Necurs.A

Posted: September 30, 2011

Threat Metric

Ranking: 14,475
Threat Level: 8/10
Infected PCs: 2,389
First Seen: September 30, 2011
Last Seen: December 20, 2024
OS(es) Affected: Windows

Trojan.Necurs.A is a member of a family of rootkits with backdoor and downloader functions, letting them compromise the security of your PC for remote control and install specialized threats for other attacks. While only limited information about Trojan.Necurs.A currently is available, malware researchers have noticed its presence in recent payloads of Trojan Zeus, a well-distributed and regularly-updated spyware Trojan that focuses on compromising bank accounts. Targeted e-mail attacks and drive-by-downloads from harmful websites are the two distribution methods that seem to be at fault for the new rise in Trojan.Necurs.A infections, and malware experts consider the removal of Trojan.Necurs.A with reliable anti-malware products to be an urgent priority for your PC's safety.

The Trojan that's Happy to Weave a Curse on Your PC's Security

Trojan.Necurs.A is one of the newest versions of Necurs to be distributed with some help from other high-level PC threats. Past Necurs attacks have involved such hazards as the Blackhole Exploit Kit (a drive-by-download attacker) and WinWebSec (a family of fake security programs), whereas Trojan.Necurs.A is primarily associated with a rise in United States-targeted e-mail attacks. These attacks use fake delivery notifications and similar formats to trick victims into opening a harmful file attachment containing the Trojan Upatre. Upatre installs a variant of Zeus, which you'll know about if you've read many of our previous articles, while Zeus also installs Trojan.Necurs.A (since, besides being a potent banking Trojan, Zeus also includes functions for downloading other threats).

Trojan.Necurs.A's full capabilities still are under analysis, although malware experts estimate that Trojan.Necurs.A most likely is intended to be an anti-security measure for protecting other PC threats installed by the same e-mail. Trojan.Necurs.A may block security programs, open a backdoor vulnerability on your PC to let criminals access it, install new types of risky software or upload data stolen by other means to a criminal-controlled server.

Even though Necurs rootkits sometimes are involved with payloads that show major symptoms, like WinWebSec, these latest attacks with Trojan.Necurs.A all use PC threats that try to hide themselves. As a result, symptoms of the infection may be minimal – especially without anti-malware utilities to detect Trojan.Necurs.A.

Dispelling Trojan.Necurs.A Before It Can Expel Your Money

Trojan.Necurs.A and the other threat related to Trojan.Necurs.A are especially well-known for the advanced programming involved in their attacks and anti-security features, and also for targeting personal information such as account passwords for your bank account. Even though you may not see any obvious signs of something wrong with your computer, malware experts always consider a Trojan.Necurs.A infection to be a high-level security and privacy hazard. Deleting Trojan.Necurs.A immediately, and with proper anti-malware tools, is paramount for the future security of any infected computer.

By the raw numbers of infections, these recent attacks using Trojan.Necurs.A installations are distinctly an issue for the United States. Despite that, other countries also have been targeted, although in much smaller numbers than those for the US. Regardless, no matter where you live, opening an e-mail attachment without confirming its safety first never is wise, and malware experts consider it best to scan any suspicious attachment to block Trojan.Necurs.A, Zeus or other threat from sneaking into your hard drive.

Aliases

Trj/Dtcontx.D [Panda]Generic32.BSSV [AVG]W32/Kryptik.AYQT [Fortinet]Mal/Generic-S [Sophos]TR/Symmi.18765 [AntiVir]Trojan-Dropper.Win32.Necurs.pfa [Kaspersky]PWS-Zbot-FASG!23C68A52087F [McAfee]Dropper.Generic8.WEG [AVG]TR/Crypt.ZPACK.Gen [AntiVir]Trojan-Dropper.Win32.Necurs.pfc [Kaspersky]BackDoor.Generic15.CMMC [AVG]Win-Trojan/Necurs.59776 [AhnLab-V3]TrojWare.Win32.UMal.~A [Comodo]Troj/Necurs-M [Sophos]Rootkit.Win32.Necurs.he [Kaspersky]
More aliases (628)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Games Files\MSTS\NewRoads_V40_MSTS1_Setup.exe File name: NewRoads_V40_MSTS1_Setup.exe
Size: 18.19 MB (18194419 bytes)
MD5: fe6029c6dd77e373e51568c8c78b650e
Detection count: 497
File type: Executable File
Mime Type: unknown/exe
Path: C:\Games Files\MSTS
Group: Malware file
Last Updated: November 21, 2024
%WINDIR%\system32\drivers\2479e.sys File name: 2479e.sys
Size: 43 KB (43008 bytes)
MD5: ed8a2b1018f0b3e846b088b7bbe51585
Detection count: 82
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: January 24, 2012
%WINDIR%\system32\drivers\662f2.sys File name: 662f2.sys
Size: 58.11 KB (58112 bytes)
MD5: 4e760d8f966a1d9f3bbe4afeb336e9da
Detection count: 73
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: January 5, 2013
%WINDIR%\System32\drivers\e42239653e830f5b.sys File name: e42239653e830f5b.sys
Size: 59.77 KB (59776 bytes)
MD5: 0907292986e05a8752bc1863556d229e
Detection count: 66
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: April 17, 2013
%WINDIR%\System32\drivers\86dadcaae13b6bc6.sys File name: 86dadcaae13b6bc6.sys
Size: 59.13 KB (59136 bytes)
MD5: 279e87cc664b6e77c05560e45ef517f1
Detection count: 51
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: March 29, 2013
%WINDIR%\System32\drivers\61a57491bc0649b8.sys File name: 61a57491bc0649b8.sys
Size: 46.26 KB (46264 bytes)
MD5: 8c55911cde8dd5c45e6be123f6ceaca1
Detection count: 45
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: December 18, 2012
%WINDIR%\system32\drivers\5071c.sys File name: 5071c.sys
Size: 69.19 KB (69192 bytes)
MD5: 8f9ebee084f45c6b7378ea9c3bbbcea5
Detection count: 36
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: March 4, 2013
%TEMP%\0.3826909899607682.exe File name: 0.3826909899607682.exe
Size: 321.02 KB (321024 bytes)
MD5: 1d81e09b7dbc01068d3572ac9eb2f512
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: October 10, 2011
%WINDIR%\System32\drivers\e9ed568f444e0f0f.sys File name: e9ed568f444e0f0f.sys
Size: 63.1 KB (63104 bytes)
MD5: 45965a29086a6943c08951dc7061eeab
Detection count: 16
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: December 20, 2012
%LOCALAPPDATA%\{B88B43D0-D723-2B15-73EF-722253A721E6}\syshost.exe File name: syshost.exe
Size: 58.88 KB (58880 bytes)
MD5: 7063a79e9065bdb51072478eca7a470c
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\{B88B43D0-D723-2B15-73EF-722253A721E6}
Group: Malware file
Last Updated: April 22, 2013
%WINDIR%\System32\drivers\22a2a5937d037a2b.sys File name: 22a2a5937d037a2b.sys
Size: 70.65 KB (70656 bytes)
MD5: 075f1f21fd1dcf6c7f1144cc2e9fe3b6
Detection count: 12
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: October 17, 2012
%USERPROFILE%\Bureau\installer.exe File name: installer.exe
Size: 801.69 KB (801699 bytes)
MD5: 4250135cb2e36bbc0fd16953d8dd5b51
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Bureau
Group: Malware file
Last Updated: October 6, 2011
%SystemDrive%\Recycle.Bin\Recycle.Bin.exe File name: Recycle.Bin.exe
Size: 157.69 KB (157696 bytes)
MD5: 4fdd0faad2727aa09c87c7b0cb27354a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Recycle.Bin
Group: Malware file
Last Updated: January 20, 2022
%APPDATA%\Blammi\blammi.exe File name: blammi.exe
Size: 749.56 KB (749568 bytes)
MD5: 6c7bfaf7d9a4cdfffbe4d402c7001e56
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Blammi
Group: Malware file
Last Updated: October 5, 2011
%WINDIR%\System32\drivers\6ef24294c953172f.sys File name: 6ef24294c953172f.sys
Size: 69.88 KB (69888 bytes)
MD5: 72a6c1fd16ed06bb7b1474de33b78a49
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: September 15, 2020
%WINDIR%\System32\drivers\c7b1929d221268f1.sys File name: c7b1929d221268f1.sys
Size: 69.72 KB (69720 bytes)
MD5: 2e992a5c03ed97cf415e49e3b08ea6eb
Detection count: 4
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: October 5, 2012
%WINDIR%\System32\drivers\a657181eb7ee61.sys File name: a657181eb7ee61.sys
Size: 71.49 KB (71496 bytes)
MD5: 87a6954ec6a20cb2c6d590dbf2d18f2d
Detection count: 3
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: October 29, 2012
%WINDIR%\System32\drivers\7a513dead4b2135e.sys File name: 7a513dead4b2135e.sys
Size: 67.54 KB (67544 bytes)
MD5: f528a809992ea627e670e5c8d1c8fdff
Detection count: 1
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: October 18, 2012
121ecb4.sys File name: 121ecb4.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
41fb2af0cd745ae6.exe File name: 41fb2af0cd745ae6.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
edsmgr.exe File name: edsmgr.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files
Loading...