Home Malware Programs Worms Worm.Esfury

Worm.Esfury

Posted: October 29, 2010

Threat Metric

Threat Level: 5/10
Infected PCs: 180
First Seen: October 12, 2010
Last Seen: July 3, 2022
OS(es) Affected: Windows

Worm.Esfury is a network-aware computer worm that will attempt to replicate across an existing network. Worm.Esfury also spreads using Windows networking APIs, MAPI functions or email clients such as Microsoft Outlook. Worm.Esfury can create email messages with corrupt attachments often containing downloads of itself. Worm.Esfury entices users with messages suggesting that the recipient should open the attachment to see something interesting or important. Do not trust this cyber menace, rather remove the threat by using a reliable malware remover.

Aliases

Generic Trojan [Panda]Dropper.Generic2.AFTM [AVG]Trojan.Injector [Ikarus]Trojan/Win32.VBKrypt.gen [Antiy-AVL]Trojan.Win32.VBKrypt.hhj [Kaspersky]Win32:Dropper-gen [Avast]W32/VB.CF.gen!Eldorado [F-Prot]a variant of Win32/Injector.CPS [NOD32]Trojan [K7AntiVirus]Generic.dx!tkv [McAfee]Worm.Esfury.A [CAT-QuickHeal]Generic Worm [Panda]Dropper.Generic2.AOSM [AVG]W32/VB.fam [Fortinet]Trojan.Click [Ikarus]
More aliases (69)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Usuario1\winlogon.exe File name: winlogon.exe
Size: 53.24 KB (53248 bytes)
MD5: dd82421a6535722ed7cbf23538c31573
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Usuario1
Group: Malware file
Last Updated: October 27, 2010
%USERPROFILE%\369666E694\winlogon.exe File name: winlogon.exe
Size: 60.41 KB (60416 bytes)
MD5: ba76d54f033bb4627f20dbc2f390ed91
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\369666E694
Group: Malware file
Last Updated: November 17, 2010
%USERPROFILE%\Administrador1\winlogon.exe File name: winlogon.exe
Size: 53.76 KB (53760 bytes)
MD5: 9afdd3c9ab12d8bfe45d046d150bd47c
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Administrador1
Group: Malware file
Last Updated: July 3, 2022
%USERPROFILE%\369666E694\winlogon.exe File name: winlogon.exe
Size: 57.34 KB (57344 bytes)
MD5: d9d5839a63b8d3e5841fedb17ea9f589
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\369666E694
Group: Malware file
Last Updated: January 12, 2011
%USERPROFILE%\47E65646574737\winlogon.exe File name: winlogon.exe
Size: 55.29 KB (55296 bytes)
MD5: edd7d51ffe2581410536940a542e5648
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\47E65646574737
Group: Malware file
Last Updated: October 27, 2010
Loading...