Trojan

Trojan:Win32/Esendi.D removal

Malware Removal

The Trojan:Win32/Esendi.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Esendi.D virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Esendi.D?


File Info:

name: 9FD1D11B97DD42E866D2.mlw
path: /opt/CAPEv2/storage/binaries/e2a42fa5e3516f142709924038be28d1a6c183329170b115686ba6bd09bb334b
crc32: 422E130B
md5: 9fd1d11b97dd42e866d25e73c50e3268
sha1: 4327a8f103f6e61712546f1c8e6e4dee14c8ddda
sha256: e2a42fa5e3516f142709924038be28d1a6c183329170b115686ba6bd09bb334b
sha512: 7ada285dc616ecb496c2e766b426e8d39be5e6a01d7ef7d4257d9bf029e0418ae81cd0d0b0bb3165a5085d9e8746038134e74d0e77f9156147243eb870a987a5
ssdeep: 12288:QhL9fDJAhqNjEex1OA0BdeOtqvDJsFQxQG3yXCVcEn3cRt9+L14uhJ+dtfkmFx37:QUBFCcn9+5lT+ddFp32hy
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T18415D011F482C132D1B3187109B6B6A9466CAA30072D0DEF77CC592EBF745E27A36A77
sha3_384: 255a52a783ea4d755cc94701df798fb8bd999a9d1638806b84a059fbc224019a13a0730987ab763074934ea9af608a80
ep_bytes: 558bec837d0c017505e8b9040000ff75
timestamp: 2018-09-21 21:37:10

Version Info:

0: [No Data]

Trojan:Win32/Esendi.D also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.AdPoshel.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Adposhel.92
MicroWorld-eScanGen:Variant.Application.CoinMiner.105
FireEyeGeneric.mg.9fd1d11b97dd42e8
CAT-QuickHealPUA.AdposhelPMF.S18867856
SkyhighBehavesLike.Win32.Generic.cm
McAfeeGenericRXGU-GJ!9FD1D11B97DD
MalwarebytesAdPoshel.Adware.Advertising.DDS
VIPREGen:Variant.Application.CoinMiner.105
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Esendi.55d93ddf
CrowdStrikewin/grayware_confidence_100% (W)
ArcabitTrojan.Application.CoinMiner.105
BitDefenderThetaGen:NN.ZedlaF.36744.1q4@aKVCsxj
VirITAdware.Win32.Generic.AZX
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.Adposhel.BJ
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.Adposhel.gen
BitDefenderGen:Variant.Application.CoinMiner.105
NANO-AntivirusRiskware.Win32.Adposhel.fjutso
SUPERAntiSpywareAdware.Adposhel/Variant
AvastWin32:AdwareX-gen [Adw]
RisingAdware.Adposhel!1.B460 (CLASSIC)
EmsisoftGen:Variant.Application.CoinMiner.105 (B)
F-SecureAdware.ADWARE/Adware.Gen
ZillyaAdware.AdposhelGen.Win32.12
Trapminesuspicious.low.ml.score
SophosAdposhel (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Adposhel.kee
GoogleDetected
AviraADWARE/Adware.Gen
Antiy-AVLGrayWare[AdWare]/Win32.Adposhel.bj
Kingsoftmalware.kb.a.1000
XcitiumApplication.Win32.AdWare.Adposhel.BT@7xf11p
MicrosoftTrojan:Win32/Esendi.D
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Adposhel.gen
GDataGen:Variant.Application.CoinMiner.105
VaristW32/S-366c94ac!Eldorado
AhnLab-V3PUP/Win32.Adposhel.R243363
ALYacGen:Variant.Application.CoinMiner.105
VBA32BScope.Adware.Adposhel
Cylanceunsafe
PandaTrj/Genetic.gen
TencentWin32.AdWare.Adposhel.Osmw
YandexTrojan.GenAsa!0YmzlOHzgZw
IkarusPUA.Adposhel
MaxSecureTrojan.Adposhel.C
FortinetAdware/Symmi
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Esendi.D?

Trojan:Win32/Esendi.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment