Threat Database Trojans Trojan.Detroie.A

Trojan.Detroie.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,542
Threat Level: 80 % (High)
Infected Computers: 81
First Seen: May 3, 2017
Last Seen: July 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Detroie.A indicates that your system has been compromised by a potentially malicious program. This type of threat is generally categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. Trojans can cause significant harm to your computer and data, making it essential to understand the nature of this threat and take prompt action to remove it.

What Is Trojan.Detroie.A?

Trojan.Detroie.A, as detected, suggests a Trojan-type threat, but without more specific information, it's challenging to pinpoint its exact nature or behaviors beyond common Trojan characteristics. Trojans are known for their ability to sneak into systems by masquerading as useful applications or hiding within legitimate programs. Once inside, they can open backdoors for remote access, steal sensitive information, or install additional malware.

How Trojan.Detroie.A Operates

While the specifics of how Trojan.Detroie.A operates are not detailed here, Trojans typically operate by exploiting vulnerabilities in software or manipulating users into installing them. They can spread through various means, including email attachments, downloads from untrusted websites, or infected software installations. Once installed, a Trojan can execute a wide range of malicious activities, from data theft and spyware installation to ransomware deployment, depending on its design and the intentions of its creators.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but often include noticeable system slowdowns, frequent crashes, or the appearance of unwanted programs or toolbars in your web browser. You might also observe unusual network activity, such as increased data usage or unfamiliar connections. In some cases, the presence of a Trojan might not be immediately apparent, as it may run in the background without overt symptoms, making regular system scans crucial for detection.

  • Unexplained changes in system settings or files
  • Appearance of suspicious programs or files
  • Increased popup ads or unwanted browser redirects
  • System crashes or instability

How to Remove Trojan.Detroie.A

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any associated malware.
  3. Manually uninstall any recently installed programs that you do not recognize or that were installed around the time the Trojan was detected.
  4. Reset your web browsers (e.g., Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.Detroie.A requires a combination of the right tools and careful system management. By following the steps outlined above and maintaining vigilance through regular system scans and safe computing practices, you can protect your system from similar threats in the future. Remember, prevention is key, so always be cautious when downloading software, avoid suspicious links or email attachments, and keep your operating system and security software up to date.

Analysis Report

General information

Family Name: Trojan.Detroie.A
Signature status: No Signature

Known Samples

MD5: eebd9989b84ced0786baaf7f9c97d765
SHA1: 8512d09aba8bf8bdea41efd57f5f129d745a655a
SHA256: ADDCCBABEE5BFAC86B79769B7E6F902730650D64376FDF7CA3DC294A46787B89
File Size: 1.11 MB, 1114791 bytes
MD5: 149788fa1d4687338c75ef702e4cfd36
SHA1: bdc265a561934dbbc157317408c473ba510b019b
SHA256: 82F80F889989F72AE84DFD7239CF7CDD382E61BAEF229C64AE08F20D2B3D04C9
File Size: 1.74 MB, 1738240 bytes
MD5: 44352061f498f0dc28b1a664a1f0ff21
SHA1: e2a06f8d9d3aa858bc8d9f60d76aeb715cb3d929
SHA256: E49EA3552B386B5CB71FDD7CBC7777839D287D109F4A86F6DFF0411F32F3F4F7
File Size: 859.52 KB, 859522 bytes
MD5: 2f0506133f43187cb10cd47e43f0ff20
SHA1: f32d4e658f212d0d026e0a43258f9e6681253aea
SHA256: C87F7BD3A2DF6FA29FE47E5E64A75551BB3224349025F754D3C1716337EE58D4
File Size: 315.39 KB, 315392 bytes
MD5: a8b18483585f87c85a7a3e787769afab
SHA1: ac007fa7da070cb2798a2cf33956bb2cb316d186
SHA256: DCA0E45844BCAC83ADB43FF0B675E0F3CFFBF9CB876FA4BEA71B56B0A82F4F24
File Size: 1.68 MB, 1678848 bytes
Show More
MD5: 931556ca1994f95c12fe30aafdce83a0
SHA1: b886d2a06a11cbd9b4c4b696e9e3beed6173bd22
SHA256: 73ACA713C737E8B6200163EDFB2FF1CBF96C1A492DF12712DD1F7B649BDB8BC7
File Size: 629.76 KB, 629756 bytes
MD5: 334a9a6acd34f9bfde85426a4092af01
SHA1: 7526666a760c6e3e16bb579f6080638afb074aca
SHA256: 816A194A653CA0232C111AD720F694286D6DFB708B4BA5B6C507973577122F51
File Size: 1.67 MB, 1671168 bytes
MD5: e91608123b383ba279c7311e98b60495
SHA1: 74527de209c147c87fc2037895eed8810b31d936
SHA256: 0D4E0711F46B08FE37795169121640AD708F96C351F2F43536F997EAEF127E08
File Size: 362.50 KB, 362496 bytes
MD5: 822c9db7c64b0e07cd3b2a5e2a59a7b6
SHA1: 3b2def2d0a11ab61e80084c3863163df74851ae8
SHA256: 990C05DDEABD3E141600F8CFE8783C29E3576B174942B4A7AAA88A18554C64F9
File Size: 2.16 MB, 2156544 bytes
MD5: 069c3e50851ed5a0b770a3abccd25953
SHA1: 6a4d8deb1402fd1151d50adb98dcf3e2bea2169f
SHA256: 973099391CF846FAACED8C6F643F3A6F98F1DB90A3E4D4D975E04A35ED8CDDFE
File Size: 957.95 KB, 957952 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Visit Wheatworks.com for Financial Math Made Easy!
Company Name
  • Slaven Radic
  • Wheatworks Software, LLC
File Description
  • Free APR Calculator executable
  • Poco Executable
File Version
  • 2.1.0.0
  • 1.2.0.601
Internal Name FAPR2100.exe
Legal Copyright
  • Copyright © 1997 - 2004 by Wheatworks Software, LLC
  • © 1998-99 by Slaven Radic
Original Filename
  • FAPR2100.exe
  • poco.exe
Product Name
  • Free APR Calculator
  • Poco
Product Version
  • 2.1.00
  • 1.2
U R L http://www.pocomail.com/

File Traits

  • ASPack v2.1
  • HighEntropy
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 2,639
Potentially Malicious Blocks: 55
Whitelisted Blocks: 2,469
Unknown Blocks: 115

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? ? 0 x x 0 x 0 0 0 x 0 0 0 x x 0 x 0 ? ? x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 ? x x 0 0 x 0 x x x ? ? x x x x x x 0 x x ? x x 0 0 0 ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 ? ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? x 0 x x 0 0 0 0 0 0 0 0 0 0 0 ? x x x x x x 0 0 x 0 x ? x 0 ? 0 ? 0 ? x x 0 0 0 x 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
\device\namedpipe\srvsvc Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_16.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_idx.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\gl_3177.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gl_f3e6.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\glf3591.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\glf3591.tmp Synchronize,Write Data
Show More
c:\users\user\appdata\local\temp\glf35b1.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\glf35b1.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\glff7f0.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\glff7f0.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\glff810.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\glff810.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\glg3590.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\glgf7df.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~glh0002.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~glh0003.tmp Generic Write,Read Attributes
c:\windows\syswow64\glbsinst.%$d Generic Write,Read Attributes
c:\windows\~glc0000.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\~glh0000.tmp Generic Write,Read Attributes
c:\windows\~glh0001.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\##10.200.31.10#amas::_labelfromdesktopini RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Winsock2
  • WSAStartup

Related Posts

Trending

Most Viewed

Loading...