Home / malware Trojan:Win32/Sefnit.CE
First posted on 27 May 2014.
Source: MicrosoftAliases :
There are no other names known for Trojan:Win32/Sefnit.CE.
Explanation :
Threat behavior
Installation
Trojan:Win32/Sefnit.CE creates the following files on your PC:
\dfrg\def_32_101.zip \dfrg\pkill.exe \dfrg\task_registrar.exe - detected as Trojan:Win32/Sefnit.CF \dfrg\upd.exe - detected as Trojan:Win32/Sefnit.CG - c:\documents and settings\administrator\local settings\temp\1.txt
- c:\documents and settings\administrator\local settings\temp\nszf.tmp\inetc.dll
- c:\documents and settings\administrator\local settings\temp\nszf.tmp\nsisdl.dll
- c:\documents and settings\administrator\local settings\temp\nszf.tmp\nsisunz.dll
- c:\documents and settings\administrator\local settings\temp\nszf.tmp\nsrandom.dll
- c:\documents and settings\administrator\local settings\temp\nszf.tmp\utils_plugin.dll - detected as Trojan:Win32/Sefnit.CE
Payload
Contacts remote hosts
Trojan:Win32/Sefnit.CE may contact the following remote hosts using port 80:
- cloud.gridprocessing.net
- jobs2.gridprocessing.net
Commonly, malware does this to:This malware description was produced and published using automated analysis of file SHA1 43eee66eecde5385c57b946d79a6fa4e78e9d297.Symptoms
- Confirm Internet connectivity
- Report a new infection to its author
- Receive configuration or other data
- Download and run files, including updates or other malware
- Receive instructions from a remote hacker
- Upload data taken from your PC
System changes
The following could indicate that you have this threat on your PC:
- You have these files:
\dfrg\def_32_101.zip
\dfrg\pkill.exe
\dfrg\task_registrar.exe
\dfrg\upd.exe
c:\documents and settings\administrator\local settings\temp\1.txt
c:\documents and settings\administrator\local settings\temp\nszf.tmp\inetc.dll
c:\documents and settings\administrator\local settings\temp\nszf.tmp\nsisdl.dll
c:\documents and settings\administrator\local settings\temp\nszf.tmp\nsisunz.dll
c:\documents and settings\administrator\local settings\temp\nszf.tmp\nsrandom.dll
c:\documents and settings\administrator\local settings\temp\nszf.tmp\utils_plugin.dllLast update 27 May 2014