Monday, January 26, 2009

Bankpatch Trojan

Removing Bankpatch
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Bankpatch Also known as:

[Kaspersky]Trojan-Downloader.Win32.Agent.dfi;
[Other]Trojan.Bankpatch!inf,W32/Malware.APOT,Mal/Generic-A

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\kerdmp.ini
[%SYSTEM%]\korg.ini
[%SYSTEM%]\ldshfr.old
[%SYSTEM%]\mentid.dmp
[%SYSTEM%]\nwkr.ini
[%SYSTEM%]\nwwnt.ini
[%SYSTEM%]\windmp.ini
[%SYSTEM%]\worg.ini
[%SYSTEM%]\kerdmp.ini
[%SYSTEM%]\korg.ini
[%SYSTEM%]\ldshfr.old
[%SYSTEM%]\mentid.dmp
[%SYSTEM%]\nwkr.ini
[%SYSTEM%]\nwwnt.ini
[%SYSTEM%]\windmp.ini
[%SYSTEM%]\worg.ini

How to detect Bankpatch:

Files:
[%SYSTEM%]\kerdmp.ini
[%SYSTEM%]\korg.ini
[%SYSTEM%]\ldshfr.old
[%SYSTEM%]\mentid.dmp
[%SYSTEM%]\nwkr.ini
[%SYSTEM%]\nwwnt.ini
[%SYSTEM%]\windmp.ini
[%SYSTEM%]\worg.ini
[%SYSTEM%]\kerdmp.ini
[%SYSTEM%]\korg.ini
[%SYSTEM%]\ldshfr.old
[%SYSTEM%]\mentid.dmp
[%SYSTEM%]\nwkr.ini
[%SYSTEM%]\nwwnt.ini
[%SYSTEM%]\windmp.ini
[%SYSTEM%]\worg.ini

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings

Removing Bankpatch:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing Bancos.GDZ Trojan
Spiderman Worm Removal
LipGame Adware Cleaner
Remove Win32.Gatez Trojan
SillyDl.CEL Trojan Removal

No comments: