Home Malware Programs Trojans Packed.Win32.PePatch.iu

Packed.Win32.PePatch.iu

Posted: March 10, 2011

Packed.Win32.PePatch.iu is a mischievous computer trojan parasite that injects rootkit components into Windows processes to evade detection. Packed.Win32.PePatch.iu will drop and download some computer threats when it is executed. Once your computer is corrupted by Packed.Win32.PePatch.iu, you will constantly get irritating pop-up advertisement while browsing web pages or you will be redirected to criminal websites.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %PROGRAM_FILES%\Packed.Win32.PePatch.iu
    2 %System%\NateOnMainA.dll
    3 %Temp%\del19853.bat
    4 %Temp%\del2fb0f.bat
    5 %Temp%\del331a0.bat
    6 %Windir%\system\Lcomres.dat
    7 %Windir%\system\Lins.log
    8 %Windir%\system\winpingying.ime
    9 %Windir%\system\winweng.exe
    10 c:\Documents and Settings\All Users\Packed.Win32.PePatch.iu \
    11 c:\Documents and Settings\All Users\Start Menu\Packed.Win32.PePatch.iu \

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Packed.Win32.PePatch.iuHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\systment
Loading...