Threat Database Trojans Trojan SEFNIT

Trojan SEFNIT

By Domesticus in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 24,915
First Seen: November 22, 2011
Last Seen: November 10, 2023
OS(es) Affected: Windows

Trojan SEFNIT is a browser hijacker Trojan that affects Mozilla and Internet Explorer. Trojan SEFNIT spreads via spam email messages, file-sharing networks and instant messaging applications. Trojan SEFNIT may also come bundled with shareware programs that are hosted on file-sharing networks. Trojan SEFNIT blocks your activity on search engines or redirects your search results to malicious websites. Trojan SEFNIT creates a .dll file and adds it into processes of Mozilla and Internet Explorer. Trojan SEFNIT also creates mutex and startup registry entries. Trojan SEFNIT runs every time you start up Windows. Remove Trojan SEFNIT immediately after detection.

SpyHunter Detects & Remove Trojan SEFNIT

File System Details

Trojan SEFNIT may create the following file(s):
# File Name MD5 Detections
1. 81D0.tmp bf6054d16bbce96159f8cbbde8ea80b3 2,186
2. stub.exe 8e564285162383f3d5d527143b2c172d 1,347
3. updater.dll 4dafef3ebbf2c25a4cc61ca086c0acbb 1,339
4. updater.dll a88c2b605442756d541d89ad1a44e835 1,205
5. updater.dll 8bb68f9c5b6df2b6f94f96ff865e5643 1,170
6. updater.dll 0afe083d8a6435fa7bdac372bfebdabd 1,139
7. updater.dll 6e8410d59d578fd8105e63ab2e6604aa 879
8. updater.dll 899e801652357e203c8569e3460bf476 875
9. updater.dll a000c005bdc9e7d6c37142316359b668 609
10. updater.dll 6593a27bef46b18794276ed29732cdb7 551
11. BleServicesCtrl.exe 283bc11ed03732ba1055aaced9f7ced8 206
12. BleServicesCtrl.exe daad2e8981ed6c9c1bcefd4f6d9c705c 110
13. BleServicesCtrl.exe 6a207b6ad9ba7ebca9d6d77123ec4e06 106
14. updater.dll 628636e673992dcbb8224fab841536ec 93
15. wins.exe 85dd3b4fc99b56c8d81d946351c19001 74
16. wins.exe 6e5564622fb62a50d8317f9860d3725d 56
17. wins.exe b59f49a8fa37d1c8d0890c7e29b66c3f 53
18. wins.exe 698adcda1e59411b4e93bf1a94041b60 52
19. wins.exe 64bf4541ca61a8a227691381f49ab3a1 51
20. wins.exe c0bba2a3786bccd0d75a03759bac50cb 45
21. updater.dll b99fe4761f454b4e25e86152b4b51784 41
22. wins.exe a5aa69f547c5e24529e64f0fd97d2544 38
23. BleServicesCtrl.exe ec8a836787b9e6197e8ea46a893a5ff7 35
24. wins.exe 7d60bc72c525b377068706c235f9cdc5 35
25. wins.exe 24d6b5f33617c651532bb08382f27095 34
26. BleServicesCtrl.exe d5f729540c886e0c1211ef381c507913 28
27. updater.dll a33881b3f5af894cfb14530224085ca5 18
28. stub.exe 097eb079e308240c60f1777eb44bd390 4
29. stub.exe 24c2573af8b38dc88fb933ae12c9e40b 2
30. %AppData%\audiop2psound\audiop2psound.dll
31. %UserProfile%\Application Data\acxmapdb\AgerePadClock.dll
More files

Registry Details

Trojan SEFNIT may create the following registry entry or registry entries:
Regexp file mask
%APPDATA%\Microsoft\ApplicationManager\stub.exe
%APPDATA%\Updater\updater.dll
%WINDIR%\system32\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe
%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"cleansweep.exe" = "rundll32.exe "%AppData%\audiop2psound\audiop2psound.dll"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"AgerePadClock" = "rundll32.exe "%USERAPPDATA%\acxmapdb\AgerePadClock.dll",isaAuthenticationInit SyncWISupport"
HKEY_CLASSES_ROOT\CLSID\{4fc3d0c1-7d9a-4c56-aa94-d5eb3997e46e}

Related Posts

Trending

Most Viewed

Loading...