Trojan.Win32.Patched.ka

By JubileeX in Trojans | 6 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

Trojan.Win32.Patched.ka Description

Trojan.Win32.Patched.ka is highly dangerous rootkit trojan program made to open a large security loophole through which a number of malicious malware infections can infiltrate your system. Trojan.Win32.Patched.ka will download files to the computer without user’s consent which will lead to security danger. Trojan.Win32.Patched.ka can even enable an attacker to gain remote access to the corrupted computer system. The types of operations are limited by user privileges on the affected computer, which typically involves modification or deletion of files, data theft, keystroke logging, and use of a PC as part of a botnet to execute mass spamming or to deliver Denial-of-service attacks.

Type: Trojans

How Can You Detect Trojan.Win32.Patched.ka?

Trojan.Win32.Patched.ka Removal Details

Trojan.Win32.Patched.ka has typically the following processes in memory:

  • %AppData%\data.dat,%AppData%\SEXY.exe

Trojan.Win32.Patched.ka creates the following files in the system:

  • c:\Documents and Settings\All Users\Start Menu\Trojan.Win32.Patched.ka \
  • c:\Documents and Settings\All Users\Trojan.Win32.Patched.ka \
  • %Temp%\IXP000.TMP\SEXY.exe,%Temp%\1.tmp
  • %PROGRAM_FILES%\Trojan.Win32.Patched.ka

Trojan.Win32.Patched.ka creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{C7BAADA4-DC89-B5DA-ABC2-C9BAD66F8AAF}
  • HKEY_LOCAL_MACHINE\Software\Trojan.Win32.Patched.ka
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C7BAADA4-DC89-B5DA-ABC2-C9BAD66F8AAF}

Important Article Disclaimer

ESG Support Center

This entry was last updated on 03/4/11 and posted on 03/4/11. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.