Crack Trojan

Trojan.Win32.Patched.mf removal tips

Malware Removal

The Trojan.Win32.Patched.mf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Patched.mf virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Patched.mf?


File Info:

name: 0CC96C1B97EB68499DC0.mlw
path: /opt/CAPEv2/storage/binaries/b8362b23617d266edbafaa9877fb9f215a8f734ad39bbd3fc87e55e681190ad8
crc32: D45B53BC
md5: 0cc96c1b97eb68499dc040fa85b0248f
sha1: 09d27099ec475bd6d41be8a0b7488fe22259848e
sha256: b8362b23617d266edbafaa9877fb9f215a8f734ad39bbd3fc87e55e681190ad8
sha512: fd9234b86502f2c8d447ac66e6ac31ae0c6ae206eb898a3f5dda75825870246d3e1dd80519dcfa3940cba9826231904dd5fe6060795c3e3e836223558e74c6c4
ssdeep: 384:yNN7aCY8CtBcelBcowXeeYOvqMqyGmojWcGOB:yciqyGmeWEB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E92C82173D4837AE8FA0B704C7653815272B9416935EB1E49C9020E7EB2E6ACF72773
sha3_384: 5b0b76954372f4619affc32e7b58ca126b008c7bd82e937fda9da8d37d7c355bf9e025bcdf43b4ecc0e83abeca047493
ep_bytes: 684e3e0011e934060000e80f00000043
timestamp: 2007-09-05 16:53:46

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Intuit
FileDescription: QuickBooks Company File Monitoring Service
FileVersion: 2.0.2804.16013
InternalName: QBCFMonitorService.exe
LegalCopyright: © 2007 Intuit Inc. All rights reserved.
LegalTrademarks: QuickBooks(TM) is a registered trademark of Intuit Inc.
OriginalFilename: QBCFMonitorService.exe
ProductName: QuickBooks for Windows
ProductVersion: 2.0.2804.16013
Assembly Version: 2.0.2804.16013

Trojan.Win32.Patched.mf also known as:

BkavW32.PatchedZB.PE
LionicTrojan.Win32.Patched.lnqW
MicroWorld-eScanTrojan.Patched.HE
CAT-QuickHealW32.Patchload.O
ALYacTrojan.Patched.HE
CylanceUnsafe
ZillyaTrojan.Patched.Win32.23985
K7AntiVirusTrojan ( 0026f5d91 )
K7GWTrojan ( 0026f5d91 )
Cybereasonmalicious.b97eb6
BaiduWin32.Virus.Loader.l
VirITWin32.Yoshi.E
CyrenW32/Patched.G
SymantecTrojan.Paccyn!inf
Elasticmalicious (high confidence)
ESET-NOD32Win32/Patched.HN
APEXMalicious
ClamAVWin.Trojan.Patched-143
KasperskyTrojan.Win32.Patched.mf
BitDefenderTrojan.Patched.HE
NANO-AntivirusTrojan.Win32.Patched.dwgwe
AvastWin32:Patched-WQ [Trj]
TencentVirus.Win32.Patched.mf
Ad-AwareTrojan.Patched.HE
ComodoTrojWare.Win32.Patched.HN@3bsert
DrWebTrojan.Starter.1695
VIPRETrojan.Patched.HE
TrendMicroPTCH_KATUSHA.W
McAfee-GW-EditionW32/Katusha
FireEyeTrojan.Patched.HE
SophosW32/Patched-AL
GDataTrojan.Patched.HE
JiangminTrojanSpy.Zbot.adxr
AviraW32/Patchload.A
Antiy-AVLTrojan/Generic.ASVirus.2BD
ArcabitTrojan.Patched.HE
ViRobotWin32.Patched.BE
MicrosoftVirus:Win32/Patchload.O
TACHYONVirus/W32.Patched.Gen
AhnLab-V3Win-Trojan/Patched.DD
McAfeeW32/Katusha
MAXmalware (ai score=87)
VBA32Trojan-Spy.Zbot.gen
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPTCH_KATUSHA.W
RisingVirus.Loader!1.9B09 (CLASSIC)
YandexWin32.Katusha.Gen
IkarusVirus.Win32.Patchload
MaxSecureVirus.W32.Patched.MF
FortinetW32/Patched.MF!tr
AVGWin32:Patched-WQ [Trj]
PandaW32/Katusha.BN

How to remove Trojan.Win32.Patched.mf?

Trojan.Win32.Patched.mf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment