QUICK LINKS Solution | Understanding New Pattern Format
--------------------------------------------------------------------------------
Virus type: Trojan
Destructive: No
Aliases: Downloader.Esepor.AF, PMS/TMKSoft.Adw.3, Adware-Xplugin, TrojanDownloader.Win32.Esepor.u
Pattern file needed: 1.926.25
Scan engine needed: 6.810
Overall risk rating: Very Low
--------------------------------------------------------------------------------
Reported infections: Low
Damage Potential: Low
Distribution Potential: Low
--------------------------------------------------------------------------------
Description:
This Trojan has a .DLL file component, which it registers as an Internet Explorer (IE) plugin, allowing it to automatically execute every time IE loads. Analysis shows that this .DLL file works in conjunction with a file named, TMKSRVU.EXE. Note, however, that this description is based mostly on analysis done on the .DLL component.
Its codes contain links to certain sites, which may indicate that it connects to the sites without the user’s permission.
It also appears to gather information regarding queries from users accessing the following search engines:
google.com
yahoo.com
altavista.com
msn.com
search.aol
It runs on Windows 95, 98, ME, NT, 2000, and XP.
Solution:
Note: The following clean instructions are applicable only to the Trojan's .DLL component.
Important Windows ME/XP Cleaning Instructions
Running Trend Micro Antivirus
Scan your system with Trend Micro antivirus and delete all files detected as TROJ_ESEPOR.U. To do this, Trend Micro customers must download the latest pattern file and scan their system. Other Internet users can use HouseCall, Trend Micro’s free online virus scanner.
(Note: Close ALL Internet Explorer sessions before proceeding with next instructions.)
Unregistering the Malware Component
The following instructions serve to remove the registered .DLL file:
Click Start>Run.
Type the following:
REGSVR32 /u <path and file name of .DLL file detected as TROJ_ESEPOR.U>
Trend Micro offers best-of-breed antivirus and content-security solutions for your , or .
For additional information about this threat, see Technical Details.