Crack Trojan

About “Trojan:Win32/Patched.W” infection

Malware Removal

The Trojan:Win32/Patched.W is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Patched.W virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Patched.W?


File Info:

name: 7F650C9588D9F23787C5.mlw
path: /opt/CAPEv2/storage/binaries/ce269ca6293bfa621fd2adf05373bc605a1af59537aa80f0f4364662b4a25ae3
crc32: 29A3B375
md5: 7f650c9588d9f23787c5c55002ec1bbf
sha1: c3542e1355abafad4ba3ce8f5a8036f76d46f2f8
sha256: ce269ca6293bfa621fd2adf05373bc605a1af59537aa80f0f4364662b4a25ae3
sha512: f8898e45e9b026c41d54bb629d63f98ac4957329945f0c9a971bde6a1052ff4b2fe44f9d08be2bb459786a3e389633e4d78e7ed4cd360c23c96fbc79e3b26d22
ssdeep: 6144:JBaZA6AM5tm1BS4i4jARHKhyFxQZZxbUP10glX1Wx:JcA6SbVi42BFx8dUP1fi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10884D1C7111AA6E4E91CC837644330BA27C26DA65E0FAD61715DFF332DB20E46E0A937
sha3_384: 735272e6b5f205201027ed268a7086d574ba6eb74e425c149b3bb48b1e50372f4853624e5300dfdc7a4beb64180c3dc4
ep_bytes: 558bec83ec20535657e8220100008bf0
timestamp: 2008-11-14 22:00:00

Version Info:

FileDescription:
FileVersion: 0.0.0.2
Internal Name: KHATRA
Original File Name: KHATRA.EXE
Translation: 0x0809 0x04b0

Trojan:Win32/Patched.W also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Patched.lizw
tehtrisGeneric.Malware
MicroWorld-eScanWin32.Fignya.A
FireEyeGeneric.mg.7f650c9588d9f237
CAT-QuickHealTrojan.Patched.IV
SkyhighW32/Autorun.worm.bcb
McAfeeW32/Autorun.worm.bcb
Cylanceunsafe
ZillyaTrojan.Patched.Win32.134535
SangforTrojan.Win32.Patched.lh
K7AntiVirusEmailWorm ( 004c70361 )
AlibabaTrojan:Win32/Fignya.afa3e2f4
K7GWEmailWorm ( 004c70361 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitWin32.Fignya.A
BaiduWin32.Virus.Fignya.a
VirITTrojan.Win32.Autoit.B
SymantecW32.Harakit
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Fignya.B
CynetMalicious (score: 99)
APEXMalicious
KasperskyTrojan.Win32.Patched.lh
BitDefenderWin32.Fignya.A
NANO-AntivirusVirus.Win32.Fignya.wfze
SUPERAntiSpywareTrojan.Agent/Gen-Fignya
AvastWin32:Sality [Inf]
TencentVirus.Win32.Patched.hjd
SophosTroj/Agent-ADVF
F-SecureTrojan.TR/AutoIt.tkw
DrWebTrojan.Siggen10.1832
VIPREWin32.Fignya.A
TrendMicroTROJ_GEN.F9BEZB9
EmsisoftWin32.Fignya.A (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/PcClient.adaw
WebrootW32.Malware.Gen
VaristW32/Fignya.A.gen!Eldorado
AviraTR/AutoIt.tkw
Antiy-AVLTrojan/Win32.Fignya
KingsoftWin32.PatchP.wz.1840
XcitiumTrojWare.Win32.Patched.PM@4kenbb
MicrosoftTrojan:Win32/Patched.W
ZoneAlarmTrojan.Win32.Patched.lh
GDataWin32.Fignya.A
GoogleDetected
AhnLab-V3Worm/Win32.Sohanad.R61655
BitDefenderThetaAI:FileInfector.24EBAC550E
ALYacWin32.Fignya.A
MAXmalware (ai score=100)
VBA32TrojanDropper.Autoit
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Patched.BA
ZonerTrojan.Win32.71880
TrendMicro-HouseCallTROJ_GEN.F9BEZB9
RisingTrojan.Win32.Autoit.dzd (CLASSIC)
YandexWin32.Ruirui.Gen
IkarusWin32.Fignya
MaxSecureVirus.W32.Patched.LH
FortinetW32/AutoRun.B!worm
AVGWin32:Sality [Inf]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Patched.W?

Trojan:Win32/Patched.W removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment