Threat Database Trojans Trojan.Tatanarg.B

Trojan.Tatanarg.B

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 6
First Seen: May 11, 2012
OS(es) Affected: Windows

Trojan.Tatanarg.B is a Trojan that aims at stealing confidential data from the affected PC. When Trojan.Tatanarg.B is executed, it creates and distributes malevolent files on the corrupted PC system. Trojan.Tatanarg.B then either distributes or downloads the particular files, which involve Trojan modules in encrypted form. Trojan.Tatanarg.B modifies the Windos Registry by creating some registry entries, so that it can start automatically whenever you boot up Windows. Trojan.Tatanarg.B controls browsing habits on the infected computer in order to gather information about accessed websites. Trojan.Tatanarg.B gathers personal details that include financial banking information and transfers it to remote cybercriminals. Gathered data may cover data on all processes running and website browsing histories. Trojan.Tatanarg.B may also use bogus certificates to sign its binaries. Uninstall Trojan.Tatanarg.B as soon as possible.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Adware/FakeAV
AVG Generic28.BWFX
Ikarus Trojan-Spy.Win32.Zbot
AhnLab-V3 Spyware/Win32.Zbot
Antiy-AVL Trojan/Win32.Zbot.gen
McAfee-GW-Edition Generic.dx!b2v4
AntiVir TR/Rogue.kdv.658594
DrWeb BackDoor.Hermes.2
Comodo TrojWare.Win32.Trojan.Agent.Gen
BitDefender Trojan.Generic.KDV.658594
Kaspersky Trojan-Spy.Win32.Zbot.eaud
Avast Win32:Malware-gen
Symantec Trojan.Tatanarg.B
F-Prot W32/Backdoor2.HKXT
NOD32 a variant of Win32/Kryptik.AHIY

SpyHunter Detects & Remove Trojan.Tatanarg.B

File System Details

Trojan.Tatanarg.B may create the following file(s):
# File Name MD5 Detections
1. Upgrade.exe e149bf28deadc18eff1d3e565fc251d8 6
2. %Temp%\ke64dlbzxln.exe
3. %Temp%\ke64dmlaci.exe
4. %Temp%\ke64fufyjr.exe
5. %UserProfile%\Application Data\Help\comm.tll
6. %Temp%\2.m.log
7. %UserProfile%\Application Data\Help\coredb\[DATE AND TIME]_[RANDOM CHARACTERS]
8. %Temp%\1.m.log
9. %UserProfile%\Application Data\Help\ceptr.tll
10. virus.rar 5fdae355282e095be359b8991e93aef5 0

Registry Details

Trojan.Tatanarg.B may create the following registry entry or registry entries:
HKEY_CURRENT_USER\System\Core2Inner\2\"Path" = "%UserProfile%\Application Data\Help\ceptr.tll"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\"KeApplet" = "%Temp%\ke64wtkh.exe"
HKEY_CURRENT_USER\System\Core2\2\"Path" = "%UserProfile%\Application Data\Help\ceptr.tll"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\"KeApplet" = "%Temp%\ke64fufyjr.exe"
HKEY_CURRENT_USER\System\Core2\1\"Path" = "%UserProfile%\Application Data\Help\comm.tll"

Trending

Most Viewed

Loading...