Home Malware Programs Trojans Trojan:Win32/Sefnit.AC

Trojan:Win32/Sefnit.AC

Posted: December 27, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 1,621
First Seen: December 27, 2011
Last Seen: May 20, 2024
OS(es) Affected: Windows

Trojan:Win32/Sefnit.AC is a browser hijacker that monitors your online activities so that Trojan:Win32/Sefnit.AC can redirect you to malicious or advertisement-based websites. Redirect attacks by Trojan:Win32/Sefnit.AC are especially-likely to take place after any attempted visit to a popular search website like Google, Bing or Yahoo Search. Because Trojan:Win32/Sefnit.AC uses injection techniques to avoid the presence of a separate memory process you should use anti-malware products to detect and delete Trojan:Win32/Sefnit.AC from your PC. Contact with sites that are espoused by Trojan:Win32/Sefnit.AC should be avoided as potential hazards for your computer's safety since they may host phishing attacks, drive-by-download attacks or other forms of hostile content.

Sniffing Out All the Harm That Trojan:Win32/Sefnit.AC Can Cause

Trojan:Win32/Sefnit.AC was detected late in December of 2011 and may not be removable by out-of-date anti-malware applications. Unlike browser hijackers that are flexible enough to attack all web browsers, Trojan:Win32/Sefnit.AC is designed for the specific purpose of infecting the processes for Internet Explorer and Mozilla Firefox. Other web browsers are currently-immune to all known versions of Trojan:Win32/Sefnit.AC. However, affected browsers are, after Trojan:Win32/Sefnit.AC's installation, infected by Trojan:Win32/Sefnit.AC's code and will proceed to run Trojan:Win32/Sefnit.AC whenever they launch themselves. Although deleting these browsers will also stop Trojan:Win32/Sefnit.AC attacks, SpywareRemove.com malware researchers discourage this form of solution, since Trojan:Win32/Sefnit.AC's components will remain on your hard drive along with related PC threats that may have installed Trojan:Win32/Sefnit.AC.

Trojan:Win32/Sefnit.AC's one and only purpose is to hijack search results, especially for MSN and Google's search engines. Trojan:Win32/Sefnit.AC's browser hijackers may block security-related sites, display fake errors or take you to malicious websites. As a result, SpywareRemove.com malware experts note that browsing the web while Trojan:Win32/Sefnit.AC is on your PC is extremely-hazardous. You may be able to detect Trojan:Win32/Sefnit.AC by the usage of unusual RAM for your browser's memory process although usage of an anti-malware program is preferable.

How Trojan:Win32/Sefnit.AC Got to You

Trojan:Win32/Sefnit.AC is usually installed by a Trojan dropper that exploits JavaScript-based vulnerabilities. Disabling Java for untrustworthy sources (such as suspicious websites or unusual pop-up advertisements) or even keeping Java up-to-date to eliminate security holes are both serviceable methods of protecting your PC from Trojan:Win32/Sefnit.AC downloads. SpywareRemove.com malware researchers recommend that you avoid launching IE or Firefox while Trojan:Win32/Sefnit.AC is on your PC since this will complicate the removal of Trojan:Win32/Sefnit.AC.

If you have up-to-date anti-malware software, removing Trojan:Win32/Sefnit.AC should be an unchallenging job. SpywareRemove.com malware experts also recommend taking extra steps to insure that PC threats aren't alert while you scan your PC for Trojan:Win32/Sefnit.AC – Safe Mode, which is available on any Windows computer, should suffice. Trojan:Win32/Sefnit.AC's original file may be named in the form of a fake 'UtilHelpSnap.dll' system component that should be considered to be malicious.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%eifnz9fgm.exe File name: %Temp%eifnz9fgm.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%lpmu6gmn.exe File name: %Temp%lpmu6gmn.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%8xkm0knw.exe File name: %Temp%8xkm0knw.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%efx9j.log File name: %Temp%efx9j.log
Mime Type: unknown/log
Group: Malware file
%ProgramFiles%Common FilesWMWMSpeech.dll File name: %ProgramFiles%Common FilesWMWMSpeech.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%Common FilesWM File name: %ProgramFiles%Common FilesWM
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{89721a77-988b-43cb-81e4-89c101e44f15}InprocServer32HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{89721a77-988b-43cb-81e4-89c101e44f15}InprocServer32](Default) = "%ProgramFiles%Common FilesWMWMSpeech.dll" ThreadingModel = "Apartment"
Loading...