Home Malware Programs Trojans Trojan.Win32.Menti.gkkn

Trojan.Win32.Menti.gkkn

Posted: July 7, 2011

Trojan.Win32.Menti.gkkn is a backdoor Trojan that exploits the Windows Registry to attack your web browser and PC security. Although you not see Trojan.Win32.Menti.gkkn while it's active, any Trojan.Win32.Menti.gkkn infection is a severe threat to your computer that could enable criminals to launch remote attacks. Remote attacks can steal private information such as passwords, destroy portions of your computer or force your computer to take part in crimes such as DDoS attacks. Until you've removed Trojan.Win32.Menti.gkkn from your PC with a reputable security application, it's recommended that you treat all information and files on your computer as potentially compromised.

Trojan.Win32.Menti.gkkn: An Intricate Abuser of Your Windows Registry

Trojan.Win32.Menti.gkkn displays limited traits that are readily observable, but those who are willing to do a little Registry-scanning will quickly learn that Trojan.Win32.Menti.gkkn's presence is highly undesirable. Some of the attacks that Trojan.Win32.Menti.gkkn has been confirmed to use via the Windows Registry include:

  • Trojan.Win32.Menti.gkkn may alter the account access and priority settings for certain file types and programs. This behavior is strongly associated with W32/Fakerean Trojans and rogue security programs like XP Anti-Virus 2012, Vista Anti-Virus 2012 and Win 7 Internet Security 2010.
  • Trojan.Win32.Menti.gkkn has also been seen using the Registry to alter Internet Explorer settings. This may prevent IE from launching, disable IE's security features or allow Trojan.Win32.Menti.gkkn to hijack it and redirect you to malicious websites.
  • Last but far from least, Trojan.Win32.Menti.gkkn has been noted to attack the Windows Security Center via the Registry, often for the purpose of disabling the Windows Firewall and anti-virus features.

How to Tell if Trojan.Win32.Menti.gkkn is the Attacker That's Hiding Out on Your PC

If you think you have a Trojan.Win32.Menti.gkkn on your computer, look for signs like the ones below:

  • The presence of unusual files in your Application Data folders (both profile-specific and 'all users' variants of these folders), your Temp folder, or your Templates folder. Trojan.Win32.Menti.gkkn typically obscures these files by placing them inside folders with lengthy and randomized file names.
  • The presence of an ebi.exe file in the aforementioned locations or an ebi.exe memory process. This is the primary Trojan.Win32.Menti.gkkn file, and to date, Trojan.Win32.Menti.gkkn has made no attempts to hide this process from being seen. You can view processes like Trojan.Win32.Menti.gkkn's own ebi.exe by accessing the Task Manager with Ctrl+Alt+Del and checking the Processes tab.
  • The presence of rogue security programs like the ones noted earlier and many other bearing similar naming schemes. Rogue applications that are installed by Trojan.Win32.Menti.gkkn may create fake alerts, block programs or hijack your browser to redirect it towards a harmful website.

The vast amounts of Trojan.Win32.Menti.gkkn Registry changes are harmful to your computer's security if left alone, but improperly undoing these Trojan.Win32.Menti.gkkn changes may cause even more serious system problems. You should fix your Registry and the rest of your PC by removing Trojan.Win32.Menti.gkkn with a qualified anti-virus or security program while keeping an eye out for other PC threats that Trojan.Win32.Menti.gkkn may have installed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\ebi.exe
    2 %AppData%\l7t6ti8pp70s47u7gksonsd4575wa2bn86
    3 %CommonAppData%\l7t6ti8pp70s47u7gksonsd4575wa2bn86
    4 %Temp%\l7t6ti8pp70s47u7gksonsd4575wa2bn86
    5 %Templates%\l7t6ti8pp70s47u7gksonsd4575wa2bn86

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Classes\.exeHKEY_CURRENT_USER\Software\Classes\.exe\DefaultIconHKEY_CURRENT_USER\Software\Classes\.exe\shellHKEY_CURRENT_USER\Software\Classes\.exe\shell\openHKEY_CURRENT_USER\Software\Classes\.exe\shell\open\commandHKEY_CURRENT_USER\Software\Classes\.exe\shell\runasHKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\commandHKEY_CURRENT_USER\Software\Classes\exefileHKEY_CURRENT_USER\Software\Classes\exefile\DefaultIconHKEY_CURRENT_USER\Software\Classes\exefile\shellHKEY_CURRENT_USER\Software\Classes\exefile\shell\openHKEY_CURRENT_USER\Software\Classes\exefile\shell\open\commandHKEY_CURRENT_USER\Software\Classes\exefile\shell\runasHKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command
Loading...